HASSH Fingerprint
5f904648ee8964bef0e8834012e26003
SSH client fingerprint (MD5 of KEX algorithms). Matching HASSH across actors indicates shared client tooling — often the same botnet, scanner, or attacker toolkit.
Actors
6
Sessions
492
First Seen
2026-02-22 20:13
Last Seen
2026-06-16 23:52
Top Countries
MX
2
GB
1
NL
1
TW
1
US
1
Top ASNs
TOTAL PLAY TELECOMUNICACIONES SA DE CV
2
The Infrastructure Group B.V.
1
Omegatech LTD
1
Feo Prest SRL
1
UAB Host Baltic
1
| IP Address | Behavior | Confidence | Flags | Events | Country | Hostname | Last Seen |
|---|---|---|---|---|---|---|---|
| 91.224.92.17 | opportunistic_bruter | 51% | DROP 1x | 39 | GB | — | 2026-06-16 23:52 |
| 130.12.180.51 | data_exfiltrator | 75% | DROP | 5546 | US | — | 2026-06-14 22:15 |
| 213.209.159.158 | credential_harvester | 78% | DROP 1x | 10228 | TW | — | 2026-06-13 20:40 |
| 186.96.145.241 | credential_harvester | 42% | 31811 | MX | — | 2026-06-07 09:04 | |
| 5.255.117.250 | credential_probe | 11% | 5 | NL | — | 2026-04-13 12:06 | |
| 187.191.2.214 | credential_probe | 16% | 1x | 5 | MX | — | 2026-04-13 11:29 |