← Back to feed

52.176.138.197

Threat Confidence
40%
Location
🇺🇸 US / Des Moines
ASN
AS8075 · Microsoft Corporation
Cloud Provider
Microsoft Azure
Total Events
37
Average by volume
Agent Count
1
First / Last Seen
2026-04-13 08:10 — 2026-04-13 11:01
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Initial Access
Credential Access
Discovery
External Corroboration
Not flagged by any external feeds
Campaigns
Not associated with any campaigns
Session Forensics
reconnaissance ×4 credential_harvester ×1
Sessions
5 (4 with login)
Avg Depth Score
0.55
Commands Executed
4
Files Downloaded
0
Notable Commands
  • uptime
  • uname -a
  • hostname
Fingerprints
16443846184eafde36765c9bab2f4397
SSH-2.0-Go
Evidence Timeline
Reconnaissance 50b7f242eed6 w4m_seattle_01 · 2026-04-13 11:01
1 1 60%
Loading events...
Reconnaissance 7a7ae879ca25 w4m_seattle_01 · 2026-04-13 10:14
1 1 60%
Loading events...
Reconnaissance 110b309ba60b w4m_seattle_01 · 2026-04-13 09:34
1 1 60%
Loading events...
Reconnaissance 7066aa79cae3 w4m_seattle_01 · 2026-04-13 08:46
1 1 60%
Loading events...
Credential Harvester a09fc73e0bab w4m_seattle_01 · 2026-04-13 08:10
1 35%
Loading events...