← Back to feed

31.56.209.39

Threat Confidence
38%
Location
🇦🇪 AE
ASN
AS209373 · Swissnet LLC
Cloud Provider
Total Events
12
Below average by volume
Agent Count
1
First / Last Seen
2026-04-18 13:20 — 2026-04-18 13:20
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Initial Access
Credential Access
Discovery
Command and Control
External Corroboration
Not flagged by any external feeds
Campaigns
Multi-Agent Scan SCAN Active medium
6 IPs 127 events
2026-03-29 — ongoing · 6 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
66 IPs 92329 events
2026-03-09 — ongoing · 66 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
68 IPs 88041 events
2026-03-09 — ongoing · 68 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
34 IPs 6048 events
2026-03-09 — ongoing · 34 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
68 IPs 88386 events
2026-03-09 — ongoing · 68 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
65 IPs 98149 events
2026-03-09 — ongoing · 65 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
10 IPs 3219 events
2026-03-05 — ongoing · 10 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
32 IPs 5935 events
2026-03-01 — ongoing · 32 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
6 IPs 1174 events
2026-03-01 — ongoing · 6 IPs independently targeted the same honeypot sensors within a 24-hour window. Hosted on Linode. Scanning the same …
Session Forensics
reconnaissance ×2
Sessions
2 (2 with login)
Avg Depth Score
0.6
Commands Executed
8
Files Downloaded
0
Notable Commands
  • echo "cat /proc/1/mounts && ls /proc/1/; curl2; ps aux; ps" | sh
  • cat /proc/1/mounts && ls /proc/1/; curl2; ps aux; ps
  • curl2
  • CMD:
Fingerprints
SSH-2.0-Go
Evidence Timeline
Reconnaissance 7a56d326bc7f w4m_seattle_01 · 2026-04-18 13:20
4 1 60%
Loading events...
Reconnaissance 198b185fef57 w4m_singapore_01 · 2026-04-17 18:39
4 1 60%
Loading events...