← Back to feed

91.92.40.6

TAGGED MALICIOUS how we decide →
Threat Confidence
68%
Location
🇳🇱 NL / Eygelshoven
ASN
AS197170 · TechTies Inc.
Cloud Provider
Total Events
230
Above average by volume
Agent Count
2
First / Last Seen
2026-06-17 20:17 — 2026-06-21 09:31
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Execution
Credential Access
Discovery
External Corroboration
Blocklist.de
Reported 2026-06-21 12:03
blocklist_de:reported
DShield Top Attackers
Reported 2026-06-21 12:01
dshield:top_attacker
Campaigns
Subnet 91.92.40.0/24 SUBNET Active high 🇳🇱 NL
16 IPs 17041 events
ftp:bruteforcessh:bruteforce
2026-06-10 — ongoing · 16 IPs from the same /24 subnet (91.92.40.0/24) were observed attacking our sensors within the same time window. …
Multi-Agent Scan SCAN Active medium
55 IPs 83519 events
2026-04-25 — ongoing · 55 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
132 IPs 176080 events
2026-04-10 — ongoing · 132 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
18 IPs 4200 events
2026-03-05 — ongoing · 18 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
53 IPs 67813 events
2026-03-01 — ongoing · 53 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
15 IPs 7399 events
2026-03-01 — ongoing · 15 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
67 IPs 80337 events
2026-02-28 — ongoing · 67 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
60 IPs 13504 events
2026-02-28 — ongoing · 60 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
8 IPs 6769 events
2026-02-26 — ongoing · 8 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
49 IPs 54437 events
2026-02-26 — ongoing · 49 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Session Forensics
scanner ×3 credential_probe ×13 interactive_operator ×18
Sessions
34 (18 with login)
Avg Depth Score
0.57
Commands Executed
90
Files Downloaded
0
Notable Commands
  • export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c "^processor" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E "model name|Hardware" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,"",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo "UNAME:$uname"; echo "ARCH:$arch"; echo "UPTIME:$uptime"; echo "CPUS:$cpus"; echo "CPU_MODEL:$cpu_model"; echo "GPU:$gpu_info"; echo "CAT_HELP:$cat_help"; echo "LS_HELP:$ls_help"; echo "LAST:$last_output"
  • uname -s -v -n -m 2 > /dev/null
  • uname -m 2 > /dev/null
  • cat /proc/uptime 2 > /dev/null | cut -d. -f1
  • cut -d. -f1
Fingerprints
SSH-2.0-Go
Evidence Timeline
Interactive Operator e3550f6ee2af w4m_singapore_01 · 2026-06-21 09:31
5 1 90%
Loading events...
Interactive Operator 5d83c7b4b7ab w4m_singapore_01 · 2026-06-21 09:29
5 1 90%
Loading events...
Interactive Operator c059fc327abd w4m_singapore_01 · 2026-06-21 09:27
5 1 90%
Loading events...
Interactive Operator 2cea06e13361 w4m_singapore_01 · 2026-06-21 09:26
5 1 90%
Loading events...
Interactive Operator f62c52cd23c1 w4m_singapore_01 · 2026-06-21 09:24
5 1 90%
Loading events...
Interactive Operator bc77b87f4760 w4m_singapore_01 · 2026-06-21 09:22
5 1 90%
Loading events...
Interactive Operator 56b327e28d65 w4m_singapore_01 · 2026-06-21 09:20
5 1 90%
Loading events...
Interactive Operator a4e5f3c3d3e5 w4m_singapore_01 · 2026-06-21 09:18
5 1 90%
Loading events...
Interactive Operator f95d8aced8a2 w4m_singapore_01 · 2026-06-21 09:16
5 1 90%
Loading events...
Interactive Operator 9baa32943555 w4m_singapore_01 · 2026-06-21 09:14
5 1 90%
Loading events...
Interactive Operator 48031d8b8499 w4m_singapore_01 · 2026-06-21 09:12
5 1 90%
Loading events...
Interactive Operator 1c394da4bda6 w4m_singapore_01 · 2026-06-21 09:11
5 1 90%
Loading events...
Interactive Operator 5a14468f0db3 w4m_singapore_01 · 2026-06-21 09:09
5 1 90%
Loading events...
Interactive Operator 902db54542bb w4m_singapore_01 · 2026-06-21 09:07
5 1 90%
Loading events...
Interactive Operator 5da31148053c w4m_singapore_01 · 2026-06-21 09:05
5 1 90%
Loading events...
Credential Probe c35cb70609ef w4m_singapore_01 · 2026-06-21 09:03
1 20%
Loading events...
Interactive Operator 01a966622120 w4m_singapore_01 · 2026-06-21 09:01
5 1 90%
Loading events...
Interactive Operator 8b48c46102ef w4m_singapore_01 · 2026-06-21 08:59
5 1 90%
Loading events...
Interactive Operator f09239866628 w4m_singapore_01 · 2026-06-21 08:57
5 1 90%
Loading events...
Scanner 4d4158639a4f w4m_singapore_01 · 2026-06-21 08:53
15%
Loading events...
Credential Probe 2696e28e6cfb w4m_seattle_01 · 2026-06-19 20:10
1 20%
Loading events...
Credential Probe 8a64c25c8950 w4m_seattle_01 · 2026-06-19 20:06
1 20%
Loading events...
Credential Probe 0ea7bda45e0f w4m_seattle_01 · 2026-06-19 20:05
1 20%
Loading events...
Credential Probe 2aac20014d07 w4m_seattle_01 · 2026-06-19 20:03
1 20%
Loading events...
Credential Probe e4b580b00217 w4m_seattle_01 · 2026-06-19 20:02
1 20%
Loading events...
Credential Probe 5c718a7b6697 w4m_seattle_01 · 2026-06-19 20:01
1 20%
Loading events...
Credential Probe 60b3b8ca9cb0 w4m_seattle_01 · 2026-06-19 19:59
1 20%
Loading events...
Credential Probe c0b966cbb1a7 w4m_seattle_01 · 2026-06-19 19:58
1 20%
Loading events...
Credential Probe 4c99eab1f148 w4m_seattle_01 · 2026-06-19 19:56
1 20%
Loading events...
Credential Probe 3055af6e3eed w4m_seattle_01 · 2026-06-19 19:55
1 20%
Loading events...
Credential Probe db92dc6c0f19 w4m_seattle_01 · 2026-06-19 19:53
1 20%
Loading events...
Scanner c73100c6d41e w4m_seattle_01 · 2026-06-19 19:51
15%
Loading events...
Credential Probe 9cdd5b1068b8 w4m_seattle_01 · 2026-06-17 20:20
1 20%
Loading events...
Scanner f64d95f167a3 w4m_seattle_01 · 2026-06-17 20:17
15%
Loading events...