← Back to feed
Location
🇺🇸 US / Greenbrier
ASN
AS7029 · Windstream Communications LLC
Cloud Provider
—
Total Events
34
Average by volume
Agent Count
1
First / Last Seen
2026-05-17 20:29 — 2026-05-17 20:29
Attack Types
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Execution
External Corroboration
Blocklist.de
blocklist_de:reported
Campaigns
Multi-Agent Scan
SCAN
Active
medium
10 IPs
2169 events
2026-03-11 — ongoing · 10 IPs independently targeted the same honeypot sensors within a 24-hour window. Hosted on Linode. Scanning the same …
Multi-Agent Scan
SCAN
Active
medium
58 IPs
320296 events
2026-03-01 — ongoing · 58 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan
SCAN
Active
medium
82 IPs
453221 events
2026-02-24 — ongoing · 82 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan
SCAN
Active
medium
3 IPs
409 events
2026-02-24 — ongoing · 3 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan
SCAN
Active
medium
84 IPs
440458 events
2026-02-24 — ongoing · 84 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan
SCAN
Active
medium
82 IPs
403820 events
2026-02-24 — ongoing · 82 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan
SCAN
Active
medium
90 IPs
453947 events
2026-02-23 — ongoing · 90 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Session Forensics
Sessions
2 (1 with login)
Avg Depth Score
0.53
Commands Executed
10
Files Downloaded
0
Notable Commands
- /ip cloud print
- ifconfig
- uname -a
- cat /proc/cpuinfo
- ps | grep '[Mm]iner'
- ps -ef | grep '[Mm]iner'
- ls -la ~/.local/share/TelegramDesktop/tdata /home/*/.local/share/TelegramDesktop/tdata /dev/ttyGSM* /dev/ttyUSB-mod* /var/spool/sms/* /var/log/smsd.log /etc/smsd.conf* /usr/bin/qmuxd /var/qmux_connect_socket /etc/config/simman /dev/modem* /var/config/sms/*
- locate D877F783D5D3EF8Cs
- echo Hi | cat -n
Fingerprints
HASSH
SSH Client
Evidence Timeline
Interactive Operator
88c432456d71
LOGIN
10
2
90%
Loading events...
HASSH f45fb203c31069b…
SSH-2.0-libssh2_1.11.1
$ /ip cloud print$ /ip cloud print$ ifconfig$ uname -a$ cat /proc/cpuinfo