← Back to feed

195.214.235.55

TAGGED SUSPICIOUS how we decide →
Threat Confidence
59%
Location
🇮🇷 IR
ASN
AS59623 · Zarin Amol Gozar Technology Development Co., Ltd
Cloud Provider
Total Events
438
Top 10% by volume
Agent Count
1
First / Last Seen
2026-06-19 00:00 — 2026-06-19 01:11
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Defense Evasion
Credential Access
Command and Control
External Corroboration
Blocklist.de
Reported 2026-06-19 04:01
blocklist_de:reported
Session Forensics
malware_dropper ×11 credential_probe ×17 opportunistic_bruter ×9
Sessions
37 (20 with login)
Avg Depth Score
0.51
Commands Executed
33
Files Downloaded
11
Notable Commands
  • cd ~; chattr -ia .ssh; lockr -ia .ssh
  • lockr -ia .ssh
  • cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEArDp4cun2lhr4KUhBGE7VvAcwdli2a8dbnrTOrbMz1+5O73fcBOx8NVbUT0bUanUV9tJ2/9p7+vD0EpZ3Tz/+0kX34uAx1RV/75GVOmNx+9EuWOnvNoaJe0QXxziIg9eLBHpgLMuakb5+BgTFB+rKJAw9u9FSTDengvS8hX1kNFS4Mjux0hJOK8rvcEmPecjdySYMb66nylAKGwCEE6WEQHmd1mUPgHwGQ0hWCwsQk13yCGPK5w6hYp5zYkFnvlC8hGmd4Ww+u97k6pfTGTUbJk14ujvcD9iUKQTTWYYjIIu5PmUux5bsZ0R4WFwdIe6+i6rBLAsPKgAySVKPRK+oRw== mdrfckr">>.ssh/authorized_keys && chmod -R go= ~/.ssh && cd ~
Fingerprints
SSH-2.0-libssh_0.9.6
Evidence Timeline
Opportunistic Bruter 91a0642ec5f9 newark_01 · 2026-06-19 01:09
1 50%
Loading events...
Malware Dropper c85f1d39b055 newark_01 · 2026-06-19 01:09
3 1 1 100%
Loading events...
Opportunistic Bruter e2875d6ae712 newark_01 · 2026-06-19 01:07
1 50%
Loading events...
Malware Dropper 00f37cce0b42 newark_01 · 2026-06-19 01:07
3 1 1 100%
Loading events...
Credential Probe ccf16be926a3 newark_01 · 2026-06-19 01:07
1 20%
Loading events...
Malware Dropper fa8a609cc8e3 newark_01 · 2026-06-19 01:05
3 1 1 100%
Loading events...
Opportunistic Bruter 77cf8763d242 newark_01 · 2026-06-19 01:05
1 50%
Loading events...
Malware Dropper fd9ab289bcb9 newark_01 · 2026-06-19 01:03
3 1 1 100%
Loading events...
Opportunistic Bruter c7195fbf8756 newark_01 · 2026-06-19 01:04
1 50%
Loading events...
Credential Probe f03723e7571c newark_01 · 2026-06-19 01:04
1 20%
Loading events...
Malware Dropper f62ff8884d87 newark_01 · 2026-06-19 01:02
3 1 1 100%
Loading events...
Credential Probe d0a33b3bb373 newark_01 · 2026-06-19 01:02
1 20%
Loading events...
Credential Probe d83d9b571f1f newark_01 · 2026-06-19 01:00
1 20%
Loading events...
Opportunistic Bruter 6b96043f4651 newark_01 · 2026-06-19 00:58
1 50%
Loading events...
Malware Dropper 5bb81b3be049 newark_01 · 2026-06-19 00:58
3 1 1 100%
Loading events...
Credential Probe ddd3fe8cf047 newark_01 · 2026-06-19 00:58
1 20%
Loading events...
Credential Probe 0731c1305f34 newark_01 · 2026-06-19 00:54
1 20%
Loading events...
Credential Probe db4d8f9b8962 newark_01 · 2026-06-19 00:52
1 20%
Loading events...
Credential Probe cc0e8490529a newark_01 · 2026-06-19 00:51
1 20%
Loading events...
Credential Probe 5f40145f2879 newark_01 · 2026-06-19 00:49
1 20%
Loading events...
Malware Dropper 723f42d100b2 newark_01 · 2026-06-19 00:45
3 1 1 100%
Loading events...
Credential Probe b04fd4499483 newark_01 · 2026-06-19 00:45
1 20%
Loading events...
Opportunistic Bruter db46f32d76b1 newark_01 · 2026-06-19 00:41
1 50%
Loading events...
Credential Probe ff63a4407854 newark_01 · 2026-06-19 00:41
1 20%
Loading events...
Malware Dropper 12c86f3ebb2a newark_01 · 2026-06-19 00:39
3 1 1 100%
Loading events...
Opportunistic Bruter 720369bee7ec newark_01 · 2026-06-19 00:39
1 50%
Loading events...
Malware Dropper bc061be46817 newark_01 · 2026-06-19 00:38
3 1 1 100%
Loading events...
Opportunistic Bruter ec546196bb63 newark_01 · 2026-06-19 00:38
1 50%
Loading events...
Credential Probe d5c913cf3237 newark_01 · 2026-06-19 00:33
1 20%
Loading events...
Opportunistic Bruter c2a66830b47a newark_01 · 2026-06-19 00:31
1 50%
Loading events...
Malware Dropper cce51dcda17f newark_01 · 2026-06-19 00:31
3 1 1 100%
Loading events...
Malware Dropper 26b9dca07c2e newark_01 · 2026-06-19 00:29
3 1 1 100%
Loading events...
Credential Probe a050af7a9df4 newark_01 · 2026-06-19 00:24
1 20%
Loading events...
Credential Probe 19ff9bed0a43 newark_01 · 2026-06-19 00:22
1 20%
Loading events...
Credential Probe fe1f603bdef2 newark_01 · 2026-06-19 00:19
1 20%
Loading events...
Credential Probe ad0b2d60d045 newark_01 · 2026-06-19 00:17
1 20%
Loading events...
Credential Probe fc7f4211e96a newark_01 · 2026-06-19 00:00
1 20%
Loading events...