← Back to feed

91.92.40.12

TAGGED MALICIOUS how we decide →
Threat Confidence
54%
Location
🇳🇱 NL / Eygelshoven
ASN
AS197170 · TechTies Inc.
Cloud Provider
Total Events
192
Above average by volume
Agent Count
1
First / Last Seen
2026-06-18 04:50 — 2026-06-18 05:33
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Execution
Credential Access
Discovery
External Corroboration
Blocklist.de
Reported 2026-06-20 00:01
blocklist_de:reported
Session Forensics
scanner ×1 credential_probe ×2 interactive_operator ×14
Sessions
18 (15 with login)
Avg Depth Score
0.78
Commands Executed
75
Files Downloaded
0
Notable Commands
  • export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c "^processor" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E "model name|Hardware" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,"",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo "UNAME:$uname"; echo "ARCH:$arch"; echo "UPTIME:$uptime"; echo "CPUS:$cpus"; echo "CPU_MODEL:$cpu_model"; echo "GPU:$gpu_info"; echo "CAT_HELP:$cat_help"; echo "LS_HELP:$ls_help"; echo "LAST:$last_output"
  • uname -s -v -n -m 2 > /dev/null
  • uname -m 2 > /dev/null
  • cat /proc/uptime 2 > /dev/null | cut -d. -f1
  • cut -d. -f1
Fingerprints
SSH-2.0-Go
Evidence Timeline
Interactive Operator 0b9a2d0f1e68 w4m_seattle_01 · 2026-06-18 05:33
5 1 90%
Loading events...
Interactive Operator 7bc084c08015 w4m_seattle_01 · 2026-06-18 05:31
5 1 90%
Loading events...
Interactive Operator 004ddb58a938 w4m_seattle_01 · 2026-06-18 05:29
5 1 90%
Loading events...
Interactive Operator d67887f296d4 w4m_seattle_01 · 2026-06-18 05:26
5 1 90%
Loading events...
Interactive Operator e4849e03f133 w4m_seattle_01 · 2026-06-18 05:24
5 1 90%
Loading events...
Interactive Operator 1de71cdb1041 w4m_seattle_01 · 2026-06-18 05:21
5 1 90%
Loading events...
Interactive Operator 1ca942006369 w4m_seattle_01 · 2026-06-18 05:19
5 1 90%
Loading events...
Interactive Operator 9362e8ed0622 w4m_seattle_01 · 2026-06-18 05:17
5 1 90%
Loading events...
Interactive Operator 54d24f1dfaa5 w4m_seattle_01 · 2026-06-18 05:14
5 1 90%
Loading events...
Interactive Operator 7f33d530be9d w4m_seattle_01 · 2026-06-18 05:12
5 1 90%
Loading events...
Interactive Operator 182c5c8b0cc9 w4m_seattle_01 · 2026-06-18 05:10
5 1 90%
Loading events...
Interactive Operator 489458c8e542 w4m_seattle_01 · 2026-06-18 05:07
5 1 90%
Loading events...
Interactive Operator 2ac85c6dcb33 w4m_seattle_01 · 2026-06-18 05:05
5 1 90%
Loading events...
Credential Probe 8a321e243568 w4m_seattle_01 · 2026-06-18 05:02
1 20%
Loading events...
Interactive Operator 01ea32cb039a w4m_seattle_01 · 2026-06-18 05:00
5 1 90%
Loading events...
Interactive Operator 271296d40a4a w4m_seattle_01 · 2026-06-18 04:57
5 1 90%
Loading events...
Credential Probe 29553cb01603 w4m_seattle_01 · 2026-06-18 04:55
1 20%
Loading events...
Scanner a37bec0b3495 w4m_seattle_01 · 2026-06-18 04:50
15%
Loading events...