← Back to feed

41.250.124.66

TAGGED MALICIOUS how we decide →
Threat Confidence
36%
Location
🇲🇦 MA / Casablanca
ASN
AS36903 · Office National des Postes et Telecommunications ONPT (Maroc Telecom) / IAM
Cloud Provider
Total Events
68
Above average by volume
Agent Count
1
First / Last Seen
2026-08-27 20:36 — 2026-08-27 20:38
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Execution
Credential Access
Discovery
Exfiltration
External Corroboration
Not flagged by any external feeds
Campaigns
Not associated with any campaigns
Session Forensics
scanner ×1 credential_probe ×1 data_exfiltrator ×1 opportunistic_bruter ×1
Sessions
4 (2 with login)
Avg Depth Score
0.44
Commands Executed
14
Files Downloaded
0
Notable Commands
  • uname -a
  • hostname
  • uname -m&&pkill upnpsetup
  • chmod 777 zsvc
  • chmod 777 upnpsetup
  • sudo ./upnpsetup
  • ./upnpsetup
  • ./upnpsetup
  • sudo ./zsvc
  • ./zsvc
Fingerprints
SSH-2.0-libssh_0.9.5
Evidence Timeline
Data Exfiltrator 7996264ff058 newark_01 · 2026-08-27 20:36
14 1 90%
Loading events...
Opportunistic Bruter da57bff85fa6 newark_01 · 2026-08-27 20:36
1 50%
Loading events...
Credential Probe 6397bd99daf8 newark_01 · 2026-08-27 20:36
1 20%
Loading events...
Scanner b89a8e619e6e newark_01 · 2026-08-27 20:36
15%
Loading events...
{# Cloudflare Web Analytics — cookieless, public pages only. The context processor withholds the token from authenticated requests. #}