nonproductions.net banner
Logo
Subsystem: NO BONK

Adversarial Observation Interface

Page 56 / 1542 (77063 total records)
Passive Observation Node - Active Operational Overview
161.132.4.167
2026-05-09 17:04:00.509302 UTC
SCORE: 0

Autonomous probing activity normalized. Remote entity established connection but deferred authentication.

Record ID: 420cc11b3042
Client Version: Unknown
Engagement Duration: 0.0s
{
  "id": "420cc11b3042",
  "src_ip": "161.132.4.167",
  "start_time": "2026-05-09T17:04:00.509302Z",
  "end_time": "2026-05-09T17:04:00.512719Z",
  "duration": "0.0",
  "version": null,
  "hassh": null,
  "attempts": [],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": []
}
161.132.4.167
2026-05-09 17:03:28.387352 UTC
RECONNAISSANCE SUCCESSFUL LOGIN COMMANDS RUN SCORE: 160

Credential acceptance event recorded. Target authentication: root / 12345

Remote entity achieved interactive shell state. Command sequence (4 executed):

[obs-node]:~$ export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c "^processor" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E "model name|Hardware" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,"",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo "UNAME:$uname"; echo "ARCH:$arch"; echo "UPTIME:$uptime"; echo "CPUS:$cpus"; echo "CPU_MODEL:$cpu_model"; echo "GPU:$gpu_info"; echo "CAT_HELP:$cat_help"; echo "LS_HELP:$ls_help"; echo "LAST:$last_output"
[obs-node]:~$ uname -s -v -n -m 2 > /dev/null
[obs-node]:~$ uname -m 2 > /dev/null
[obs-node]:~$ cat /proc/uptime 2 > /dev/null | cut -d. -f1
Record ID: e9c09fa19448
Client Version: SSH-2.0-Go
Engagement Duration: 1.1s
HASSH Fingerprint: 2ec37a7cc8daf20b10e1ad6221061ca5
{
  "id": "e9c09fa19448",
  "src_ip": "161.132.4.167",
  "start_time": "2026-05-09T17:03:28.387352Z",
  "end_time": "2026-05-09T17:03:29.517476Z",
  "duration": "1.1",
  "version": "SSH-2.0-Go",
  "hassh": "2ec37a7cc8daf20b10e1ad6221061ca5",
  "attempts": [],
  "success_login": true,
  "success_credential": {
    "user": "root",
    "pass": "12345"
  },
  "commands": [
    "export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c \"^processor\" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E \"model name|Hardware\" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,\"\",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo \"UNAME:$uname\"; echo \"ARCH:$arch\"; echo \"UPTIME:$uptime\"; echo \"CPUS:$cpus\"; echo \"CPU_MODEL:$cpu_model\"; echo \"GPU:$gpu_info\"; echo \"CAT_HELP:$cat_help\"; echo \"LS_HELP:$ls_help\"; echo \"LAST:$last_output\"",
    "uname -s -v -n -m 2 > /dev/null",
    "uname -m 2 > /dev/null",
    "cat /proc/uptime 2 > /dev/null | cut -d. -f1"
  ],
  "detailed_commands": [
    {
      "cmd": "export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c \"^processor\" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E \"model name|Hardware\" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,\"\",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo \"UNAME:$uname\"; echo \"ARCH:$arch\"; echo \"UPTIME:$uptime\"; echo \"CPUS:$cpus\"; echo \"CPU_MODEL:$cpu_model\"; echo \"GPU:$gpu_info\"; echo \"CAT_HELP:$cat_help\"; echo \"LS_HELP:$ls_help\"; echo \"LAST:$last_output\"",
      "failed": false,
      "error": null
    },
    {
      "cmd": "uname -s -v -n -m 2 > /dev/null",
      "failed": false,
      "error": null
    },
    {
      "cmd": "uname -m 2 > /dev/null",
      "failed": false,
      "error": null
    },
    {
      "cmd": "cat /proc/uptime 2 > /dev/null | cut -d. -f1",
      "failed": false,
      "error": null
    }
  ],
  "failed_commands": [],
  "score": 160,
  "tags": [
    "RECONNAISSANCE",
    "SUCCESSFUL LOGIN",
    "COMMANDS RUN"
  ]
}
193.32.162.145
2026-05-09 17:03:15.674594 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (1 distinct queries). Vector identities: solana

Record ID: bcc95cab9638
Client Version: SSH-2.0-Go
Engagement Duration: 1.9s
HASSH Fingerprint: 16443846184eafde36765c9bab2f4397
{
  "id": "bcc95cab9638",
  "src_ip": "193.32.162.145",
  "start_time": "2026-05-09T17:03:15.674594Z",
  "end_time": "2026-05-09T17:03:17.557159Z",
  "duration": "1.9",
  "version": "SSH-2.0-Go",
  "hassh": "16443846184eafde36765c9bab2f4397",
  "attempts": [
    {
      "user": "solana",
      "pass": "Solana"
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}
161.132.4.167
2026-05-09 17:02:49.957720 UTC
RECONNAISSANCE SUCCESSFUL LOGIN COMMANDS RUN SCORE: 160

Credential acceptance event recorded. Target authentication: root / 1234

Remote entity achieved interactive shell state. Command sequence (4 executed):

[obs-node]:~$ export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c "^processor" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E "model name|Hardware" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,"",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo "UNAME:$uname"; echo "ARCH:$arch"; echo "UPTIME:$uptime"; echo "CPUS:$cpus"; echo "CPU_MODEL:$cpu_model"; echo "GPU:$gpu_info"; echo "CAT_HELP:$cat_help"; echo "LS_HELP:$ls_help"; echo "LAST:$last_output"
[obs-node]:~$ uname -s -v -n -m 2 > /dev/null
[obs-node]:~$ uname -m 2 > /dev/null
[obs-node]:~$ cat /proc/uptime 2 > /dev/null | cut -d. -f1
Record ID: ee1985e9f5c7
Client Version: SSH-2.0-Go
Engagement Duration: 4.3s
HASSH Fingerprint: 2ec37a7cc8daf20b10e1ad6221061ca5
{
  "id": "ee1985e9f5c7",
  "src_ip": "161.132.4.167",
  "start_time": "2026-05-09T17:02:49.957720Z",
  "end_time": "2026-05-09T17:02:54.269081Z",
  "duration": "4.3",
  "version": "SSH-2.0-Go",
  "hassh": "2ec37a7cc8daf20b10e1ad6221061ca5",
  "attempts": [],
  "success_login": true,
  "success_credential": {
    "user": "root",
    "pass": "1234"
  },
  "commands": [
    "export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c \"^processor\" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E \"model name|Hardware\" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,\"\",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo \"UNAME:$uname\"; echo \"ARCH:$arch\"; echo \"UPTIME:$uptime\"; echo \"CPUS:$cpus\"; echo \"CPU_MODEL:$cpu_model\"; echo \"GPU:$gpu_info\"; echo \"CAT_HELP:$cat_help\"; echo \"LS_HELP:$ls_help\"; echo \"LAST:$last_output\"",
    "uname -s -v -n -m 2 > /dev/null",
    "uname -m 2 > /dev/null",
    "cat /proc/uptime 2 > /dev/null | cut -d. -f1"
  ],
  "detailed_commands": [
    {
      "cmd": "export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c \"^processor\" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E \"model name|Hardware\" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,\"\",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo \"UNAME:$uname\"; echo \"ARCH:$arch\"; echo \"UPTIME:$uptime\"; echo \"CPUS:$cpus\"; echo \"CPU_MODEL:$cpu_model\"; echo \"GPU:$gpu_info\"; echo \"CAT_HELP:$cat_help\"; echo \"LS_HELP:$ls_help\"; echo \"LAST:$last_output\"",
      "failed": false,
      "error": null
    },
    {
      "cmd": "uname -s -v -n -m 2 > /dev/null",
      "failed": false,
      "error": null
    },
    {
      "cmd": "uname -m 2 > /dev/null",
      "failed": false,
      "error": null
    },
    {
      "cmd": "cat /proc/uptime 2 > /dev/null | cut -d. -f1",
      "failed": false,
      "error": null
    }
  ],
  "failed_commands": [],
  "score": 160,
  "tags": [
    "RECONNAISSANCE",
    "SUCCESSFUL LOGIN",
    "COMMANDS RUN"
  ]
}
161.132.4.167
2026-05-09 17:02:14.748345 UTC
RECONNAISSANCE SUCCESSFUL LOGIN COMMANDS RUN SCORE: 160

Credential acceptance event recorded. Target authentication: root / 123456789

Remote entity achieved interactive shell state. Command sequence (4 executed):

[obs-node]:~$ export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c "^processor" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E "model name|Hardware" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,"",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo "UNAME:$uname"; echo "ARCH:$arch"; echo "UPTIME:$uptime"; echo "CPUS:$cpus"; echo "CPU_MODEL:$cpu_model"; echo "GPU:$gpu_info"; echo "CAT_HELP:$cat_help"; echo "LS_HELP:$ls_help"; echo "LAST:$last_output"
[obs-node]:~$ uname -s -v -n -m 2 > /dev/null
[obs-node]:~$ uname -m 2 > /dev/null
[obs-node]:~$ cat /proc/uptime 2 > /dev/null | cut -d. -f1
Record ID: 562173466b97
Client Version: SSH-2.0-Go
Engagement Duration: 1.1s
HASSH Fingerprint: 2ec37a7cc8daf20b10e1ad6221061ca5
{
  "id": "562173466b97",
  "src_ip": "161.132.4.167",
  "start_time": "2026-05-09T17:02:14.748345Z",
  "end_time": "2026-05-09T17:02:15.890508Z",
  "duration": "1.1",
  "version": "SSH-2.0-Go",
  "hassh": "2ec37a7cc8daf20b10e1ad6221061ca5",
  "attempts": [],
  "success_login": true,
  "success_credential": {
    "user": "root",
    "pass": "123456789"
  },
  "commands": [
    "export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c \"^processor\" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E \"model name|Hardware\" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,\"\",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo \"UNAME:$uname\"; echo \"ARCH:$arch\"; echo \"UPTIME:$uptime\"; echo \"CPUS:$cpus\"; echo \"CPU_MODEL:$cpu_model\"; echo \"GPU:$gpu_info\"; echo \"CAT_HELP:$cat_help\"; echo \"LS_HELP:$ls_help\"; echo \"LAST:$last_output\"",
    "uname -s -v -n -m 2 > /dev/null",
    "uname -m 2 > /dev/null",
    "cat /proc/uptime 2 > /dev/null | cut -d. -f1"
  ],
  "detailed_commands": [
    {
      "cmd": "export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c \"^processor\" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E \"model name|Hardware\" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,\"\",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo \"UNAME:$uname\"; echo \"ARCH:$arch\"; echo \"UPTIME:$uptime\"; echo \"CPUS:$cpus\"; echo \"CPU_MODEL:$cpu_model\"; echo \"GPU:$gpu_info\"; echo \"CAT_HELP:$cat_help\"; echo \"LS_HELP:$ls_help\"; echo \"LAST:$last_output\"",
      "failed": false,
      "error": null
    },
    {
      "cmd": "uname -s -v -n -m 2 > /dev/null",
      "failed": false,
      "error": null
    },
    {
      "cmd": "uname -m 2 > /dev/null",
      "failed": false,
      "error": null
    },
    {
      "cmd": "cat /proc/uptime 2 > /dev/null | cut -d. -f1",
      "failed": false,
      "error": null
    }
  ],
  "failed_commands": [],
  "score": 160,
  "tags": [
    "RECONNAISSANCE",
    "SUCCESSFUL LOGIN",
    "COMMANDS RUN"
  ]
}
161.132.4.167
2026-05-09 17:02:14.634758 UTC
SCORE: 0

Autonomous probing activity normalized. Remote entity established connection but deferred authentication.

Record ID: eeec6b753834
Client Version: Unknown
Engagement Duration: 0.0s
{
  "id": "eeec6b753834",
  "src_ip": "161.132.4.167",
  "start_time": "2026-05-09T17:02:14.634758Z",
  "end_time": "2026-05-09T17:02:14.638262Z",
  "duration": "0.0",
  "version": null,
  "hassh": null,
  "attempts": [],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": []
}
87.251.64.176
2026-05-09 17:02:14.522236 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (1 distinct queries). Vector identities: support

Record ID: b202d1fa3d14
Client Version: SSH-2.0-Go
Engagement Duration: 1.9s
HASSH Fingerprint: eff4c24daffc8532c160e86e5f006e53
{
  "id": "b202d1fa3d14",
  "src_ip": "87.251.64.176",
  "start_time": "2026-05-09T17:02:14.522236Z",
  "end_time": "2026-05-09T17:02:16.395568Z",
  "duration": "1.9",
  "version": "SSH-2.0-Go",
  "hassh": "eff4c24daffc8532c160e86e5f006e53",
  "attempts": [
    {
      "user": "support",
      "pass": "support"
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}
161.132.4.167
2026-05-09 17:01:08.772852 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (1 distinct queries). Vector identities: root

Record ID: 4d96e25803f4
Client Version: SSH-2.0-Go
Engagement Duration: 1.6s
HASSH Fingerprint: 2ec37a7cc8daf20b10e1ad6221061ca5
{
  "id": "4d96e25803f4",
  "src_ip": "161.132.4.167",
  "start_time": "2026-05-09T17:01:08.772852Z",
  "end_time": "2026-05-09T17:01:10.414352Z",
  "duration": "1.6",
  "version": "SSH-2.0-Go",
  "hassh": "2ec37a7cc8daf20b10e1ad6221061ca5",
  "attempts": [
    {
      "user": "root",
      "pass": "123456"
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}
193.32.162.145
2026-05-09 17:01:06.575327 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (1 distinct queries). Vector identities: solana

Record ID: 9686a577df5a
Client Version: SSH-2.0-Go
Engagement Duration: 1.8s
HASSH Fingerprint: 16443846184eafde36765c9bab2f4397
{
  "id": "9686a577df5a",
  "src_ip": "193.32.162.145",
  "start_time": "2026-05-09T17:01:06.575327Z",
  "end_time": "2026-05-09T17:01:08.422175Z",
  "duration": "1.8",
  "version": "SSH-2.0-Go",
  "hassh": "16443846184eafde36765c9bab2f4397",
  "attempts": [
    {
      "user": "solana",
      "pass": "1234"
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}
161.132.4.167
2026-05-09 17:00:07.701228 UTC
RECONNAISSANCE SUCCESSFUL LOGIN COMMANDS RUN SCORE: 160

Credential acceptance event recorded. Target authentication: root / password

Remote entity achieved interactive shell state. Command sequence (4 executed):

[obs-node]:~$ export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c "^processor" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E "model name|Hardware" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,"",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo "UNAME:$uname"; echo "ARCH:$arch"; echo "UPTIME:$uptime"; echo "CPUS:$cpus"; echo "CPU_MODEL:$cpu_model"; echo "GPU:$gpu_info"; echo "CAT_HELP:$cat_help"; echo "LS_HELP:$ls_help"; echo "LAST:$last_output"
[obs-node]:~$ uname -s -v -n -m 2 > /dev/null
[obs-node]:~$ uname -m 2 > /dev/null
[obs-node]:~$ cat /proc/uptime 2 > /dev/null | cut -d. -f1
Record ID: d9d31bd5ad73
Client Version: SSH-2.0-Go
Engagement Duration: 5.5s
HASSH Fingerprint: 2ec37a7cc8daf20b10e1ad6221061ca5
{
  "id": "d9d31bd5ad73",
  "src_ip": "161.132.4.167",
  "start_time": "2026-05-09T17:00:07.701228Z",
  "end_time": "2026-05-09T17:00:13.179672Z",
  "duration": "5.5",
  "version": "SSH-2.0-Go",
  "hassh": "2ec37a7cc8daf20b10e1ad6221061ca5",
  "attempts": [],
  "success_login": true,
  "success_credential": {
    "user": "root",
    "pass": "password"
  },
  "commands": [
    "export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c \"^processor\" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E \"model name|Hardware\" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,\"\",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo \"UNAME:$uname\"; echo \"ARCH:$arch\"; echo \"UPTIME:$uptime\"; echo \"CPUS:$cpus\"; echo \"CPU_MODEL:$cpu_model\"; echo \"GPU:$gpu_info\"; echo \"CAT_HELP:$cat_help\"; echo \"LS_HELP:$ls_help\"; echo \"LAST:$last_output\"",
    "uname -s -v -n -m 2 > /dev/null",
    "uname -m 2 > /dev/null",
    "cat /proc/uptime 2 > /dev/null | cut -d. -f1"
  ],
  "detailed_commands": [
    {
      "cmd": "export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c \"^processor\" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E \"model name|Hardware\" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,\"\",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo \"UNAME:$uname\"; echo \"ARCH:$arch\"; echo \"UPTIME:$uptime\"; echo \"CPUS:$cpus\"; echo \"CPU_MODEL:$cpu_model\"; echo \"GPU:$gpu_info\"; echo \"CAT_HELP:$cat_help\"; echo \"LS_HELP:$ls_help\"; echo \"LAST:$last_output\"",
      "failed": false,
      "error": null
    },
    {
      "cmd": "uname -s -v -n -m 2 > /dev/null",
      "failed": false,
      "error": null
    },
    {
      "cmd": "uname -m 2 > /dev/null",
      "failed": false,
      "error": null
    },
    {
      "cmd": "cat /proc/uptime 2 > /dev/null | cut -d. -f1",
      "failed": false,
      "error": null
    }
  ],
  "failed_commands": [],
  "score": 160,
  "tags": [
    "RECONNAISSANCE",
    "SUCCESSFUL LOGIN",
    "COMMANDS RUN"
  ]
}
193.32.162.145
2026-05-09 16:58:56.815369 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (1 distinct queries). Vector identities: node

Record ID: 101b8b65d09a
Client Version: SSH-2.0-Go
Engagement Duration: 1.9s
HASSH Fingerprint: 16443846184eafde36765c9bab2f4397
{
  "id": "101b8b65d09a",
  "src_ip": "193.32.162.145",
  "start_time": "2026-05-09T16:58:56.815369Z",
  "end_time": "2026-05-09T16:58:58.723722Z",
  "duration": "1.9",
  "version": "SSH-2.0-Go",
  "hassh": "16443846184eafde36765c9bab2f4397",
  "attempts": [
    {
      "user": "node",
      "pass": "node"
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}
161.132.4.167
2026-05-09 16:58:31.511433 UTC
RECONNAISSANCE SUCCESSFUL LOGIN COMMANDS RUN SCORE: 160

Credential acceptance event recorded. Target authentication: root / admin

Remote entity achieved interactive shell state. Command sequence (4 executed):

[obs-node]:~$ export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c "^processor" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E "model name|Hardware" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,"",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo "UNAME:$uname"; echo "ARCH:$arch"; echo "UPTIME:$uptime"; echo "CPUS:$cpus"; echo "CPU_MODEL:$cpu_model"; echo "GPU:$gpu_info"; echo "CAT_HELP:$cat_help"; echo "LS_HELP:$ls_help"; echo "LAST:$last_output"
[obs-node]:~$ uname -s -v -n -m 2 > /dev/null
[obs-node]:~$ uname -m 2 > /dev/null
[obs-node]:~$ cat /proc/uptime 2 > /dev/null | cut -d. -f1
Record ID: 93213fd69b27
Client Version: SSH-2.0-Go
Engagement Duration: 1.0s
HASSH Fingerprint: 2ec37a7cc8daf20b10e1ad6221061ca5
{
  "id": "93213fd69b27",
  "src_ip": "161.132.4.167",
  "start_time": "2026-05-09T16:58:31.511433Z",
  "end_time": "2026-05-09T16:58:32.500919Z",
  "duration": "1.0",
  "version": "SSH-2.0-Go",
  "hassh": "2ec37a7cc8daf20b10e1ad6221061ca5",
  "attempts": [],
  "success_login": true,
  "success_credential": {
    "user": "root",
    "pass": "admin"
  },
  "commands": [
    "export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c \"^processor\" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E \"model name|Hardware\" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,\"\",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo \"UNAME:$uname\"; echo \"ARCH:$arch\"; echo \"UPTIME:$uptime\"; echo \"CPUS:$cpus\"; echo \"CPU_MODEL:$cpu_model\"; echo \"GPU:$gpu_info\"; echo \"CAT_HELP:$cat_help\"; echo \"LS_HELP:$ls_help\"; echo \"LAST:$last_output\"",
    "uname -s -v -n -m 2 > /dev/null",
    "uname -m 2 > /dev/null",
    "cat /proc/uptime 2 > /dev/null | cut -d. -f1"
  ],
  "detailed_commands": [
    {
      "cmd": "export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c \"^processor\" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E \"model name|Hardware\" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,\"\",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo \"UNAME:$uname\"; echo \"ARCH:$arch\"; echo \"UPTIME:$uptime\"; echo \"CPUS:$cpus\"; echo \"CPU_MODEL:$cpu_model\"; echo \"GPU:$gpu_info\"; echo \"CAT_HELP:$cat_help\"; echo \"LS_HELP:$ls_help\"; echo \"LAST:$last_output\"",
      "failed": false,
      "error": null
    },
    {
      "cmd": "uname -s -v -n -m 2 > /dev/null",
      "failed": false,
      "error": null
    },
    {
      "cmd": "uname -m 2 > /dev/null",
      "failed": false,
      "error": null
    },
    {
      "cmd": "cat /proc/uptime 2 > /dev/null | cut -d. -f1",
      "failed": false,
      "error": null
    }
  ],
  "failed_commands": [],
  "score": 160,
  "tags": [
    "RECONNAISSANCE",
    "SUCCESSFUL LOGIN",
    "COMMANDS RUN"
  ]
}
161.132.4.167
2026-05-09 16:57:14.597858 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (1 distinct queries). Vector identities: root

Record ID: a27970915177
Client Version: SSH-2.0-Go
Engagement Duration: 3.3s
HASSH Fingerprint: 2ec37a7cc8daf20b10e1ad6221061ca5
{
  "id": "a27970915177",
  "src_ip": "161.132.4.167",
  "start_time": "2026-05-09T16:57:14.597858Z",
  "end_time": "2026-05-09T16:57:17.891749Z",
  "duration": "3.3",
  "version": "SSH-2.0-Go",
  "hassh": "2ec37a7cc8daf20b10e1ad6221061ca5",
  "attempts": [
    {
      "user": "root",
      "pass": "root"
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}
193.32.162.145
2026-05-09 16:56:51.638035 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (1 distinct queries). Vector identities: validator

Record ID: 451f3581f7ef
Client Version: SSH-2.0-Go
Engagement Duration: 2.1s
HASSH Fingerprint: 16443846184eafde36765c9bab2f4397
{
  "id": "451f3581f7ef",
  "src_ip": "193.32.162.145",
  "start_time": "2026-05-09T16:56:51.638035Z",
  "end_time": "2026-05-09T16:56:53.714225Z",
  "duration": "2.1",
  "version": "SSH-2.0-Go",
  "hassh": "16443846184eafde36765c9bab2f4397",
  "attempts": [
    {
      "user": "validator",
      "pass": "validator"
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}
2.57.121.112
2026-05-09 16:54:37.469113 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (5 distinct queries). Vector identities: admin

Record ID: 67ccf78a8abd
Client Version: SSH-2.0-libssh2_1.9.0
Engagement Duration: 6.8s
HASSH Fingerprint: 57446c12547a668110aa237e5965e374
{
  "id": "67ccf78a8abd",
  "src_ip": "2.57.121.112",
  "start_time": "2026-05-09T16:54:37.469113Z",
  "end_time": "2026-05-09T16:54:44.237155Z",
  "duration": "6.8",
  "version": "SSH-2.0-libssh2_1.9.0",
  "hassh": "57446c12547a668110aa237e5965e374",
  "attempts": [
    {
      "user": "admin",
      "pass": "ravi"
    },
    {
      "user": "admin",
      "pass": "Rattolo58"
    },
    {
      "user": "admin",
      "pass": "randi"
    },
    {
      "user": "admin",
      "pass": "radost"
    },
    {
      "user": "admin",
      "pass": "qzwxecrv"
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}
193.32.162.145
2026-05-09 16:54:33.737077 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (1 distinct queries). Vector identities: ubuntu

Record ID: 7dd61054dac2
Client Version: SSH-2.0-Go
Engagement Duration: 1.9s
HASSH Fingerprint: 16443846184eafde36765c9bab2f4397
{
  "id": "7dd61054dac2",
  "src_ip": "193.32.162.145",
  "start_time": "2026-05-09T16:54:33.737077Z",
  "end_time": "2026-05-09T16:54:35.611950Z",
  "duration": "1.9",
  "version": "SSH-2.0-Go",
  "hassh": "16443846184eafde36765c9bab2f4397",
  "attempts": [
    {
      "user": "ubuntu",
      "pass": "ubuntu"
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}
193.32.162.145
2026-05-09 16:52:15.904654 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (1 distinct queries). Vector identities: solana

Record ID: c25cc8d25860
Client Version: SSH-2.0-Go
Engagement Duration: 2.2s
HASSH Fingerprint: 16443846184eafde36765c9bab2f4397
{
  "id": "c25cc8d25860",
  "src_ip": "193.32.162.145",
  "start_time": "2026-05-09T16:52:15.904654Z",
  "end_time": "2026-05-09T16:52:18.120313Z",
  "duration": "2.2",
  "version": "SSH-2.0-Go",
  "hassh": "16443846184eafde36765c9bab2f4397",
  "attempts": [
    {
      "user": "solana",
      "pass": "solana"
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}
193.32.162.145
2026-05-09 16:50:03.604868 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (1 distinct queries). Vector identities: sol

Record ID: 0058c2b4cf87
Client Version: SSH-2.0-Go
Engagement Duration: 2.1s
HASSH Fingerprint: 16443846184eafde36765c9bab2f4397
{
  "id": "0058c2b4cf87",
  "src_ip": "193.32.162.145",
  "start_time": "2026-05-09T16:50:03.604868Z",
  "end_time": "2026-05-09T16:50:05.706999Z",
  "duration": "2.1",
  "version": "SSH-2.0-Go",
  "hassh": "16443846184eafde36765c9bab2f4397",
  "attempts": [
    {
      "user": "sol",
      "pass": "sol"
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}
54.152.61.40
2026-05-09 16:49:56.324957 UTC
SCORE: 0

Autonomous probing activity normalized. Remote entity established connection but deferred authentication.

Record ID: 0cc5efc59700
Client Version: SSH-2.0-Go
Engagement Duration: 0.2s
HASSH Fingerprint: 9052c4ab4164c78256e71143dcfc7eac
{
  "id": "0cc5efc59700",
  "src_ip": "54.152.61.40",
  "start_time": "2026-05-09T16:49:56.324957Z",
  "end_time": "2026-05-09T16:49:56.514436Z",
  "duration": "0.2",
  "version": "SSH-2.0-Go",
  "hassh": "9052c4ab4164c78256e71143dcfc7eac",
  "attempts": [],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": []
}
139.19.117.197
2026-05-09 16:48:35.834934 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (2 distinct queries). Vector identities: admin

Record ID: 66738fb51793
Client Version: SSH-2.0-Go
Engagement Duration: 10.0s
HASSH Fingerprint: f1e5e9d24e5e345e8745613bde22d532
{
  "id": "66738fb51793",
  "src_ip": "139.19.117.197",
  "start_time": "2026-05-09T16:48:35.834934Z",
  "end_time": "2026-05-09T16:48:45.834152Z",
  "duration": "10.0",
  "version": "SSH-2.0-Go",
  "hassh": "f1e5e9d24e5e345e8745613bde22d532",
  "attempts": [
    {
      "user": "admin",
      "pass": null
    },
    {
      "user": "admin",
      "pass": null
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}
193.32.162.145
2026-05-09 16:46:12.892995 UTC
SCORE: 0

Autonomous probing activity normalized. Remote entity established connection but deferred authentication.

Record ID: 03e32982b556
Client Version: Unknown
Engagement Duration: 0.2s
{
  "id": "03e32982b556",
  "src_ip": "193.32.162.145",
  "start_time": "2026-05-09T16:46:12.892995Z",
  "end_time": "2026-05-09T16:46:13.062183Z",
  "duration": "0.2",
  "version": null,
  "hassh": null,
  "attempts": [],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": []
}
147.185.132.30
2026-05-09 16:33:44.954415 UTC
SCORE: 0

Autonomous probing activity normalized. Remote entity established connection but deferred authentication.

Record ID: 3353ba263079
Client Version: SSH-2.0-ZGrab ZGrab SSH Survey
Engagement Duration: 3.1s
HASSH Fingerprint: dd9bcf093c355da7000132131cb36fd0
{
  "id": "3353ba263079",
  "src_ip": "147.185.132.30",
  "start_time": "2026-05-09T16:33:44.954415Z",
  "end_time": "2026-05-09T16:33:48.041100Z",
  "duration": "3.1",
  "version": "SSH-2.0-ZGrab ZGrab SSH Survey",
  "hassh": "dd9bcf093c355da7000132131cb36fd0",
  "attempts": [],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": []
}
213.209.159.56
2026-05-09 16:32:25.675554 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (5 distinct queries). Vector identities: federico

Record ID: ee0ed8bf1b12
Client Version: SSH-2.0-libssh2_1.9.0
Engagement Duration: 6.7s
HASSH Fingerprint: 57446c12547a668110aa237e5965e374
{
  "id": "ee0ed8bf1b12",
  "src_ip": "213.209.159.56",
  "start_time": "2026-05-09T16:32:25.675554Z",
  "end_time": "2026-05-09T16:32:32.333891Z",
  "duration": "6.7",
  "version": "SSH-2.0-libssh2_1.9.0",
  "hassh": "57446c12547a668110aa237e5965e374",
  "attempts": [
    {
      "user": "federico",
      "pass": "federico"
    },
    {
      "user": "federico",
      "pass": "federico1"
    },
    {
      "user": "federico",
      "pass": "federico123"
    },
    {
      "user": "federico",
      "pass": "federico1234"
    },
    {
      "user": "federico",
      "pass": "federico12345"
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}
161.132.4.167
2026-05-09 16:31:50.775237 UTC
RECONNAISSANCE SUCCESSFUL LOGIN COMMANDS RUN SCORE: 160

Credential acceptance event recorded. Target authentication: root / password

Remote entity achieved interactive shell state. Command sequence (4 executed):

[obs-node]:~$ export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c "^processor" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E "model name|Hardware" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,"",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo "UNAME:$uname"; echo "ARCH:$arch"; echo "UPTIME:$uptime"; echo "CPUS:$cpus"; echo "CPU_MODEL:$cpu_model"; echo "GPU:$gpu_info"; echo "CAT_HELP:$cat_help"; echo "LS_HELP:$ls_help"; echo "LAST:$last_output"
[obs-node]:~$ uname -s -v -n -m 2 > /dev/null
[obs-node]:~$ uname -m 2 > /dev/null
[obs-node]:~$ cat /proc/uptime 2 > /dev/null | cut -d. -f1
Record ID: 8c735b35571d
Client Version: SSH-2.0-Go
Engagement Duration: 2.3s
HASSH Fingerprint: 2ec37a7cc8daf20b10e1ad6221061ca5
{
  "id": "8c735b35571d",
  "src_ip": "161.132.4.167",
  "start_time": "2026-05-09T16:31:50.775237Z",
  "end_time": "2026-05-09T16:31:53.036168Z",
  "duration": "2.3",
  "version": "SSH-2.0-Go",
  "hassh": "2ec37a7cc8daf20b10e1ad6221061ca5",
  "attempts": [],
  "success_login": true,
  "success_credential": {
    "user": "root",
    "pass": "password"
  },
  "commands": [
    "export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c \"^processor\" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E \"model name|Hardware\" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,\"\",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo \"UNAME:$uname\"; echo \"ARCH:$arch\"; echo \"UPTIME:$uptime\"; echo \"CPUS:$cpus\"; echo \"CPU_MODEL:$cpu_model\"; echo \"GPU:$gpu_info\"; echo \"CAT_HELP:$cat_help\"; echo \"LS_HELP:$ls_help\"; echo \"LAST:$last_output\"",
    "uname -s -v -n -m 2 > /dev/null",
    "uname -m 2 > /dev/null",
    "cat /proc/uptime 2 > /dev/null | cut -d. -f1"
  ],
  "detailed_commands": [
    {
      "cmd": "export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c \"^processor\" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E \"model name|Hardware\" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,\"\",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo \"UNAME:$uname\"; echo \"ARCH:$arch\"; echo \"UPTIME:$uptime\"; echo \"CPUS:$cpus\"; echo \"CPU_MODEL:$cpu_model\"; echo \"GPU:$gpu_info\"; echo \"CAT_HELP:$cat_help\"; echo \"LS_HELP:$ls_help\"; echo \"LAST:$last_output\"",
      "failed": false,
      "error": null
    },
    {
      "cmd": "uname -s -v -n -m 2 > /dev/null",
      "failed": false,
      "error": null
    },
    {
      "cmd": "uname -m 2 > /dev/null",
      "failed": false,
      "error": null
    },
    {
      "cmd": "cat /proc/uptime 2 > /dev/null | cut -d. -f1",
      "failed": false,
      "error": null
    }
  ],
  "failed_commands": [],
  "score": 160,
  "tags": [
    "RECONNAISSANCE",
    "SUCCESSFUL LOGIN",
    "COMMANDS RUN"
  ]
}
161.132.4.167
2026-05-09 16:30:21.648601 UTC
RECONNAISSANCE SUCCESSFUL LOGIN COMMANDS RUN SCORE: 160

Credential acceptance event recorded. Target authentication: root / admin

Remote entity achieved interactive shell state. Command sequence (4 executed):

[obs-node]:~$ export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c "^processor" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E "model name|Hardware" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,"",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo "UNAME:$uname"; echo "ARCH:$arch"; echo "UPTIME:$uptime"; echo "CPUS:$cpus"; echo "CPU_MODEL:$cpu_model"; echo "GPU:$gpu_info"; echo "CAT_HELP:$cat_help"; echo "LS_HELP:$ls_help"; echo "LAST:$last_output"
[obs-node]:~$ uname -s -v -n -m 2 > /dev/null
[obs-node]:~$ uname -m 2 > /dev/null
[obs-node]:~$ cat /proc/uptime 2 > /dev/null | cut -d. -f1
Record ID: daf67d640a88
Client Version: SSH-2.0-Go
Engagement Duration: 1.0s
HASSH Fingerprint: 2ec37a7cc8daf20b10e1ad6221061ca5
{
  "id": "daf67d640a88",
  "src_ip": "161.132.4.167",
  "start_time": "2026-05-09T16:30:21.648601Z",
  "end_time": "2026-05-09T16:30:22.639034Z",
  "duration": "1.0",
  "version": "SSH-2.0-Go",
  "hassh": "2ec37a7cc8daf20b10e1ad6221061ca5",
  "attempts": [],
  "success_login": true,
  "success_credential": {
    "user": "root",
    "pass": "admin"
  },
  "commands": [
    "export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c \"^processor\" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E \"model name|Hardware\" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,\"\",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo \"UNAME:$uname\"; echo \"ARCH:$arch\"; echo \"UPTIME:$uptime\"; echo \"CPUS:$cpus\"; echo \"CPU_MODEL:$cpu_model\"; echo \"GPU:$gpu_info\"; echo \"CAT_HELP:$cat_help\"; echo \"LS_HELP:$ls_help\"; echo \"LAST:$last_output\"",
    "uname -s -v -n -m 2 > /dev/null",
    "uname -m 2 > /dev/null",
    "cat /proc/uptime 2 > /dev/null | cut -d. -f1"
  ],
  "detailed_commands": [
    {
      "cmd": "export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c \"^processor\" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E \"model name|Hardware\" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,\"\",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo \"UNAME:$uname\"; echo \"ARCH:$arch\"; echo \"UPTIME:$uptime\"; echo \"CPUS:$cpus\"; echo \"CPU_MODEL:$cpu_model\"; echo \"GPU:$gpu_info\"; echo \"CAT_HELP:$cat_help\"; echo \"LS_HELP:$ls_help\"; echo \"LAST:$last_output\"",
      "failed": false,
      "error": null
    },
    {
      "cmd": "uname -s -v -n -m 2 > /dev/null",
      "failed": false,
      "error": null
    },
    {
      "cmd": "uname -m 2 > /dev/null",
      "failed": false,
      "error": null
    },
    {
      "cmd": "cat /proc/uptime 2 > /dev/null | cut -d. -f1",
      "failed": false,
      "error": null
    }
  ],
  "failed_commands": [],
  "score": 160,
  "tags": [
    "RECONNAISSANCE",
    "SUCCESSFUL LOGIN",
    "COMMANDS RUN"
  ]
}
161.132.4.167
2026-05-09 16:29:03.395557 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (1 distinct queries). Vector identities: root

Record ID: 97458f1dbaf5
Client Version: SSH-2.0-Go
Engagement Duration: 3.8s
HASSH Fingerprint: 2ec37a7cc8daf20b10e1ad6221061ca5
{
  "id": "97458f1dbaf5",
  "src_ip": "161.132.4.167",
  "start_time": "2026-05-09T16:29:03.395557Z",
  "end_time": "2026-05-09T16:29:07.242487Z",
  "duration": "3.8",
  "version": "SSH-2.0-Go",
  "hassh": "2ec37a7cc8daf20b10e1ad6221061ca5",
  "attempts": [
    {
      "user": "root",
      "pass": "root"
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}
192.168.0.1
2026-05-09 16:18:29.338308 UTC
SCORE: 0

Autonomous probing activity normalized. Remote entity established connection but deferred authentication.

Record ID: a890fbffa567
Client Version: Unknown
Engagement Duration: 0.0s
{
  "id": "a890fbffa567",
  "src_ip": "192.168.0.1",
  "start_time": "2026-05-09T16:18:29.338308Z",
  "end_time": "2026-05-09T16:18:29.352726Z",
  "duration": "0.0",
  "version": null,
  "hassh": null,
  "attempts": [],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": []
}
161.132.4.167
2026-05-09 16:05:27.742635 UTC
RECONNAISSANCE SUCCESSFUL LOGIN COMMANDS RUN SCORE: 160

Credential acceptance event recorded. Target authentication: root / 123456789

Remote entity achieved interactive shell state. Command sequence (4 executed):

[obs-node]:~$ export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c "^processor" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E "model name|Hardware" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,"",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo "UNAME:$uname"; echo "ARCH:$arch"; echo "UPTIME:$uptime"; echo "CPUS:$cpus"; echo "CPU_MODEL:$cpu_model"; echo "GPU:$gpu_info"; echo "CAT_HELP:$cat_help"; echo "LS_HELP:$ls_help"; echo "LAST:$last_output"
[obs-node]:~$ uname -s -v -n -m 2 > /dev/null
[obs-node]:~$ uname -m 2 > /dev/null
[obs-node]:~$ cat /proc/uptime 2 > /dev/null | cut -d. -f1
Record ID: 6c60644a3172
Client Version: SSH-2.0-Go
Engagement Duration: 2.8s
HASSH Fingerprint: 2ec37a7cc8daf20b10e1ad6221061ca5
{
  "id": "6c60644a3172",
  "src_ip": "161.132.4.167",
  "start_time": "2026-05-09T16:05:27.742635Z",
  "end_time": "2026-05-09T16:05:30.539647Z",
  "duration": "2.8",
  "version": "SSH-2.0-Go",
  "hassh": "2ec37a7cc8daf20b10e1ad6221061ca5",
  "attempts": [],
  "success_login": true,
  "success_credential": {
    "user": "root",
    "pass": "123456789"
  },
  "commands": [
    "export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c \"^processor\" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E \"model name|Hardware\" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,\"\",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo \"UNAME:$uname\"; echo \"ARCH:$arch\"; echo \"UPTIME:$uptime\"; echo \"CPUS:$cpus\"; echo \"CPU_MODEL:$cpu_model\"; echo \"GPU:$gpu_info\"; echo \"CAT_HELP:$cat_help\"; echo \"LS_HELP:$ls_help\"; echo \"LAST:$last_output\"",
    "uname -s -v -n -m 2 > /dev/null",
    "uname -m 2 > /dev/null",
    "cat /proc/uptime 2 > /dev/null | cut -d. -f1"
  ],
  "detailed_commands": [
    {
      "cmd": "export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c \"^processor\" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E \"model name|Hardware\" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,\"\",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo \"UNAME:$uname\"; echo \"ARCH:$arch\"; echo \"UPTIME:$uptime\"; echo \"CPUS:$cpus\"; echo \"CPU_MODEL:$cpu_model\"; echo \"GPU:$gpu_info\"; echo \"CAT_HELP:$cat_help\"; echo \"LS_HELP:$ls_help\"; echo \"LAST:$last_output\"",
      "failed": false,
      "error": null
    },
    {
      "cmd": "uname -s -v -n -m 2 > /dev/null",
      "failed": false,
      "error": null
    },
    {
      "cmd": "uname -m 2 > /dev/null",
      "failed": false,
      "error": null
    },
    {
      "cmd": "cat /proc/uptime 2 > /dev/null | cut -d. -f1",
      "failed": false,
      "error": null
    }
  ],
  "failed_commands": [],
  "score": 160,
  "tags": [
    "RECONNAISSANCE",
    "SUCCESSFUL LOGIN",
    "COMMANDS RUN"
  ]
}
161.132.4.167
2026-05-09 16:04:44.406751 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (1 distinct queries). Vector identities: root

Record ID: c7aa1fcc6e45
Client Version: SSH-2.0-Go
Engagement Duration: 2.7s
HASSH Fingerprint: 2ec37a7cc8daf20b10e1ad6221061ca5
{
  "id": "c7aa1fcc6e45",
  "src_ip": "161.132.4.167",
  "start_time": "2026-05-09T16:04:44.406751Z",
  "end_time": "2026-05-09T16:04:47.142037Z",
  "duration": "2.7",
  "version": "SSH-2.0-Go",
  "hassh": "2ec37a7cc8daf20b10e1ad6221061ca5",
  "attempts": [
    {
      "user": "root",
      "pass": "123456"
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}
161.132.4.167
2026-05-09 16:03:59.183076 UTC
RECONNAISSANCE SUCCESSFUL LOGIN COMMANDS RUN SCORE: 160

Credential acceptance event recorded. Target authentication: root / password

Remote entity achieved interactive shell state. Command sequence (4 executed):

[obs-node]:~$ export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c "^processor" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E "model name|Hardware" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,"",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo "UNAME:$uname"; echo "ARCH:$arch"; echo "UPTIME:$uptime"; echo "CPUS:$cpus"; echo "CPU_MODEL:$cpu_model"; echo "GPU:$gpu_info"; echo "CAT_HELP:$cat_help"; echo "LS_HELP:$ls_help"; echo "LAST:$last_output"
[obs-node]:~$ uname -s -v -n -m 2 > /dev/null
[obs-node]:~$ uname -m 2 > /dev/null
[obs-node]:~$ cat /proc/uptime 2 > /dev/null | cut -d. -f1
Record ID: 37751b66dace
Client Version: SSH-2.0-Go
Engagement Duration: 1.3s
HASSH Fingerprint: 2ec37a7cc8daf20b10e1ad6221061ca5
{
  "id": "37751b66dace",
  "src_ip": "161.132.4.167",
  "start_time": "2026-05-09T16:03:59.183076Z",
  "end_time": "2026-05-09T16:04:00.443402Z",
  "duration": "1.3",
  "version": "SSH-2.0-Go",
  "hassh": "2ec37a7cc8daf20b10e1ad6221061ca5",
  "attempts": [],
  "success_login": true,
  "success_credential": {
    "user": "root",
    "pass": "password"
  },
  "commands": [
    "export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c \"^processor\" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E \"model name|Hardware\" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,\"\",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo \"UNAME:$uname\"; echo \"ARCH:$arch\"; echo \"UPTIME:$uptime\"; echo \"CPUS:$cpus\"; echo \"CPU_MODEL:$cpu_model\"; echo \"GPU:$gpu_info\"; echo \"CAT_HELP:$cat_help\"; echo \"LS_HELP:$ls_help\"; echo \"LAST:$last_output\"",
    "uname -s -v -n -m 2 > /dev/null",
    "uname -m 2 > /dev/null",
    "cat /proc/uptime 2 > /dev/null | cut -d. -f1"
  ],
  "detailed_commands": [
    {
      "cmd": "export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c \"^processor\" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E \"model name|Hardware\" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,\"\",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo \"UNAME:$uname\"; echo \"ARCH:$arch\"; echo \"UPTIME:$uptime\"; echo \"CPUS:$cpus\"; echo \"CPU_MODEL:$cpu_model\"; echo \"GPU:$gpu_info\"; echo \"CAT_HELP:$cat_help\"; echo \"LS_HELP:$ls_help\"; echo \"LAST:$last_output\"",
      "failed": false,
      "error": null
    },
    {
      "cmd": "uname -s -v -n -m 2 > /dev/null",
      "failed": false,
      "error": null
    },
    {
      "cmd": "uname -m 2 > /dev/null",
      "failed": false,
      "error": null
    },
    {
      "cmd": "cat /proc/uptime 2 > /dev/null | cut -d. -f1",
      "failed": false,
      "error": null
    }
  ],
  "failed_commands": [],
  "score": 160,
  "tags": [
    "RECONNAISSANCE",
    "SUCCESSFUL LOGIN",
    "COMMANDS RUN"
  ]
}
161.132.4.167
2026-05-09 16:03:55.947408 UTC
SCORE: 0

Autonomous probing activity normalized. Remote entity established connection but deferred authentication.

Record ID: 96567cff8236
Client Version: Unknown
Engagement Duration: 0.1s
{
  "id": "96567cff8236",
  "src_ip": "161.132.4.167",
  "start_time": "2026-05-09T16:03:55.947408Z",
  "end_time": "2026-05-09T16:03:56.023169Z",
  "duration": "0.1",
  "version": null,
  "hassh": null,
  "attempts": [],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": []
}
2.57.122.194
2026-05-09 16:03:40.315329 UTC
SCORE: 0

Autonomous probing activity normalized. Remote entity established connection but deferred authentication.

Record ID: ebd9353b7f4f
Client Version: SSH-2.0-PUTTY
Engagement Duration: 0.9s
HASSH Fingerprint: 5bd26477da5440a6187bd3f1b39a429c
{
  "id": "ebd9353b7f4f",
  "src_ip": "2.57.122.194",
  "start_time": "2026-05-09T16:03:40.315329Z",
  "end_time": "2026-05-09T16:03:41.187301Z",
  "duration": "0.9",
  "version": "SSH-2.0-PUTTY",
  "hassh": "5bd26477da5440a6187bd3f1b39a429c",
  "attempts": [],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": []
}
161.132.4.167
2026-05-09 16:02:31.490340 UTC
RECONNAISSANCE SUCCESSFUL LOGIN COMMANDS RUN SCORE: 160

Credential acceptance event recorded. Target authentication: root / admin

Remote entity achieved interactive shell state. Command sequence (4 executed):

[obs-node]:~$ export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c "^processor" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E "model name|Hardware" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,"",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo "UNAME:$uname"; echo "ARCH:$arch"; echo "UPTIME:$uptime"; echo "CPUS:$cpus"; echo "CPU_MODEL:$cpu_model"; echo "GPU:$gpu_info"; echo "CAT_HELP:$cat_help"; echo "LS_HELP:$ls_help"; echo "LAST:$last_output"
[obs-node]:~$ uname -s -v -n -m 2 > /dev/null
[obs-node]:~$ uname -m 2 > /dev/null
[obs-node]:~$ cat /proc/uptime 2 > /dev/null | cut -d. -f1
Record ID: 62d75d715f6b
Client Version: SSH-2.0-Go
Engagement Duration: 4.0s
HASSH Fingerprint: 2ec37a7cc8daf20b10e1ad6221061ca5
{
  "id": "62d75d715f6b",
  "src_ip": "161.132.4.167",
  "start_time": "2026-05-09T16:02:31.490340Z",
  "end_time": "2026-05-09T16:02:35.523774Z",
  "duration": "4.0",
  "version": "SSH-2.0-Go",
  "hassh": "2ec37a7cc8daf20b10e1ad6221061ca5",
  "attempts": [],
  "success_login": true,
  "success_credential": {
    "user": "root",
    "pass": "admin"
  },
  "commands": [
    "export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c \"^processor\" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E \"model name|Hardware\" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,\"\",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo \"UNAME:$uname\"; echo \"ARCH:$arch\"; echo \"UPTIME:$uptime\"; echo \"CPUS:$cpus\"; echo \"CPU_MODEL:$cpu_model\"; echo \"GPU:$gpu_info\"; echo \"CAT_HELP:$cat_help\"; echo \"LS_HELP:$ls_help\"; echo \"LAST:$last_output\"",
    "uname -s -v -n -m 2 > /dev/null",
    "uname -m 2 > /dev/null",
    "cat /proc/uptime 2 > /dev/null | cut -d. -f1"
  ],
  "detailed_commands": [
    {
      "cmd": "export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:$PATH; uname=$(uname -s -v -n -m 2>/dev/null); arch=$(uname -m 2>/dev/null); uptime=$(cat /proc/uptime 2>/dev/null | cut -d. -f1); cpus=$( (nproc 2>/dev/null || /usr/bin/nproc 2>/dev/null || grep -c \"^processor\" /proc/cpuinfo 2>/dev/null) | head -1); cpu_model=$( (grep -m1 -E \"model name|Hardware\" /proc/cpuinfo | cut -d: -f2- | sed 's/^ *//;s/ *$//' ; lscpu 2>/dev/null | awk -F: '/Model name/ {gsub(/^ +| +$/,\"\",$2); print $2; exit}' ; dmidecode -s processor-version 2>/dev/null | head -n1 ; uname -p 2>/dev/null) | awk 'NF{print; exit}' ); gpu_info=$( (lspci 2>/dev/null | grep -i vga; lspci 2>/dev/null | grep -i nvidia) 2>/dev/null | head -n50); cat_help=$( (cat --help 2>&1 | tr '\\n' ' ') || cat --help 2>&1); ls_help=$( (ls --help 2>&1 | tr '\\n' ' ') || ls --help 2>&1); last_output=$(last 2>/dev/null | head -n 10); echo \"UNAME:$uname\"; echo \"ARCH:$arch\"; echo \"UPTIME:$uptime\"; echo \"CPUS:$cpus\"; echo \"CPU_MODEL:$cpu_model\"; echo \"GPU:$gpu_info\"; echo \"CAT_HELP:$cat_help\"; echo \"LS_HELP:$ls_help\"; echo \"LAST:$last_output\"",
      "failed": false,
      "error": null
    },
    {
      "cmd": "uname -s -v -n -m 2 > /dev/null",
      "failed": false,
      "error": null
    },
    {
      "cmd": "uname -m 2 > /dev/null",
      "failed": false,
      "error": null
    },
    {
      "cmd": "cat /proc/uptime 2 > /dev/null | cut -d. -f1",
      "failed": false,
      "error": null
    }
  ],
  "failed_commands": [],
  "score": 160,
  "tags": [
    "RECONNAISSANCE",
    "SUCCESSFUL LOGIN",
    "COMMANDS RUN"
  ]
}
2.57.121.25
2026-05-09 16:01:46.525339 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (5 distinct queries). Vector identities: user

Record ID: f4d203501999
Client Version: SSH-2.0-libssh2_1.9.0
Engagement Duration: 6.8s
HASSH Fingerprint: 57446c12547a668110aa237e5965e374
{
  "id": "f4d203501999",
  "src_ip": "2.57.121.25",
  "start_time": "2026-05-09T16:01:46.525339Z",
  "end_time": "2026-05-09T16:01:53.284727Z",
  "duration": "6.8",
  "version": "SSH-2.0-libssh2_1.9.0",
  "hassh": "57446c12547a668110aa237e5965e374",
  "attempts": [
    {
      "user": "user",
      "pass": "230584"
    },
    {
      "user": "user",
      "pass": "23031979"
    },
    {
      "user": "user",
      "pass": "23021995"
    },
    {
      "user": "user",
      "pass": "23021994"
    },
    {
      "user": "user",
      "pass": "230190"
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}
161.132.4.167
2026-05-09 16:00:53.389360 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (1 distinct queries). Vector identities: root

Record ID: 4a65a7d7278d
Client Version: SSH-2.0-Go
Engagement Duration: 4.3s
HASSH Fingerprint: 2ec37a7cc8daf20b10e1ad6221061ca5
{
  "id": "4a65a7d7278d",
  "src_ip": "161.132.4.167",
  "start_time": "2026-05-09T16:00:53.389360Z",
  "end_time": "2026-05-09T16:00:57.684889Z",
  "duration": "4.3",
  "version": "SSH-2.0-Go",
  "hassh": "2ec37a7cc8daf20b10e1ad6221061ca5",
  "attempts": [
    {
      "user": "root",
      "pass": "root"
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}
161.132.4.167
2026-05-09 15:59:31.660834 UTC
SCORE: 0

Autonomous probing activity normalized. Remote entity established connection but deferred authentication.

Record ID: 17eb0cda925d
Client Version: Unknown
Engagement Duration: 0.1s
{
  "id": "17eb0cda925d",
  "src_ip": "161.132.4.167",
  "start_time": "2026-05-09T15:59:31.660834Z",
  "end_time": "2026-05-09T15:59:31.775094Z",
  "duration": "0.1",
  "version": null,
  "hassh": null,
  "attempts": [],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": []
}
139.19.117.197
2026-05-09 15:48:34.947557 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (2 distinct queries). Vector identities: admin

Record ID: a2e0b4877f13
Client Version: SSH-2.0-Go
Engagement Duration: 10.0s
HASSH Fingerprint: f1e5e9d24e5e345e8745613bde22d532
{
  "id": "a2e0b4877f13",
  "src_ip": "139.19.117.197",
  "start_time": "2026-05-09T15:48:34.947557Z",
  "end_time": "2026-05-09T15:48:44.946776Z",
  "duration": "10.0",
  "version": "SSH-2.0-Go",
  "hassh": "f1e5e9d24e5e345e8745613bde22d532",
  "attempts": [
    {
      "user": "admin",
      "pass": null
    },
    {
      "user": "admin",
      "pass": null
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}
80.94.92.168
2026-05-09 15:35:48.825347 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (1 distinct queries). Vector identities: solana

Record ID: c71b30f2cf8b
Client Version: SSH-2.0-Go
Engagement Duration: 3.1s
HASSH Fingerprint: 16443846184eafde36765c9bab2f4397
{
  "id": "c71b30f2cf8b",
  "src_ip": "80.94.92.168",
  "start_time": "2026-05-09T15:35:48.825347Z",
  "end_time": "2026-05-09T15:35:51.968659Z",
  "duration": "3.1",
  "version": "SSH-2.0-Go",
  "hassh": "16443846184eafde36765c9bab2f4397",
  "attempts": [
    {
      "user": "solana",
      "pass": "solana"
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}
2.57.121.112
2026-05-09 15:34:17.487403 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (5 distinct queries). Vector identities: admin

Record ID: e3b6eea6f650
Client Version: SSH-2.0-libssh2_1.9.0
Engagement Duration: 6.8s
HASSH Fingerprint: 57446c12547a668110aa237e5965e374
{
  "id": "e3b6eea6f650",
  "src_ip": "2.57.121.112",
  "start_time": "2026-05-09T15:34:17.487403Z",
  "end_time": "2026-05-09T15:34:24.257612Z",
  "duration": "6.8",
  "version": "SSH-2.0-libssh2_1.9.0",
  "hassh": "57446c12547a668110aa237e5965e374",
  "attempts": [
    {
      "user": "admin",
      "pass": "redknapp"
    },
    {
      "user": "admin",
      "pass": "redfred"
    },
    {
      "user": "admin",
      "pass": "redeemed"
    },
    {
      "user": "admin",
      "pass": "redcloud"
    },
    {
      "user": "admin",
      "pass": "raygun"
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}
80.94.92.168
2026-05-09 15:30:15.906761 UTC
SCORE: 0

Autonomous probing activity normalized. Remote entity established connection but deferred authentication.

Record ID: bccbc3fe3cbd
Client Version: Unknown
Engagement Duration: 0.2s
{
  "id": "bccbc3fe3cbd",
  "src_ip": "80.94.92.168",
  "start_time": "2026-05-09T15:30:15.906761Z",
  "end_time": "2026-05-09T15:30:16.082077Z",
  "duration": "0.2",
  "version": null,
  "hassh": null,
  "attempts": [],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": []
}
213.209.159.56
2026-05-09 15:25:02.765731 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (5 distinct queries). Vector identities: eleazar

Record ID: 4e6ebc5457b0
Client Version: SSH-2.0-libssh2_1.9.0
Engagement Duration: 6.6s
HASSH Fingerprint: 57446c12547a668110aa237e5965e374
{
  "id": "4e6ebc5457b0",
  "src_ip": "213.209.159.56",
  "start_time": "2026-05-09T15:25:02.765731Z",
  "end_time": "2026-05-09T15:25:09.363323Z",
  "duration": "6.6",
  "version": "SSH-2.0-libssh2_1.9.0",
  "hassh": "57446c12547a668110aa237e5965e374",
  "attempts": [
    {
      "user": "eleazar",
      "pass": "eleazar"
    },
    {
      "user": "eleazar",
      "pass": "eleazar1"
    },
    {
      "user": "eleazar",
      "pass": "eleazar123"
    },
    {
      "user": "eleazar",
      "pass": "eleazar1234"
    },
    {
      "user": "eleazar",
      "pass": "eleazar12345"
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}
171.109.111.69
2026-05-09 15:22:05.259308 UTC
RECONNAISSANCE SUCCESSFUL LOGIN COMMANDS RUN SCORE: 100

Credential acceptance event recorded. Target authentication: root / ------fuck------

Remote entity achieved interactive shell state. Command sequence (1 executed):

[obs-node]:~$ uname -s -m
Record ID: ff190b489b70
Client Version: SSH-2.0-Go
Engagement Duration: 1.5s
HASSH Fingerprint: 98f63c4d9c87edbd97ed4747fa031019
{
  "id": "ff190b489b70",
  "src_ip": "171.109.111.69",
  "start_time": "2026-05-09T15:22:05.259308Z",
  "end_time": "2026-05-09T15:22:06.742315Z",
  "duration": "1.5",
  "version": "SSH-2.0-Go",
  "hassh": "98f63c4d9c87edbd97ed4747fa031019",
  "attempts": [],
  "success_login": true,
  "success_credential": {
    "user": "root",
    "pass": "------fuck------"
  },
  "commands": [
    "uname -s -m"
  ],
  "detailed_commands": [
    {
      "cmd": "uname -s -m",
      "failed": false,
      "error": null
    }
  ],
  "failed_commands": [],
  "score": 100,
  "tags": [
    "RECONNAISSANCE",
    "SUCCESSFUL LOGIN",
    "COMMANDS RUN"
  ]
}
171.109.111.69
2026-05-09 15:22:04.771703 UTC
SCORE: 0

Autonomous probing activity normalized. Remote entity established connection but deferred authentication.

Record ID: 2b76b106523d
Client Version: Unknown
Engagement Duration: 0.3s
{
  "id": "2b76b106523d",
  "src_ip": "171.109.111.69",
  "start_time": "2026-05-09T15:22:04.771703Z",
  "end_time": "2026-05-09T15:22:05.064343Z",
  "duration": "0.3",
  "version": null,
  "hassh": null,
  "attempts": [],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": []
}
63.229.76.169
2026-05-09 15:11:13.194964 UTC
SCORE: 0

Autonomous probing activity normalized. Remote entity established connection but deferred authentication.

Record ID: 42f8ad3f3d83
Client Version: Unknown
Engagement Duration: 0.0s
{
  "id": "42f8ad3f3d83",
  "src_ip": "63.229.76.169",
  "start_time": "2026-05-09T15:11:13.194964Z",
  "end_time": "2026-05-09T15:11:13.212320Z",
  "duration": "0.0",
  "version": null,
  "hassh": null,
  "attempts": [],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": []
}
77.90.185.16
2026-05-09 15:03:29.460030 UTC
SCORE: 0

Autonomous probing activity normalized. Remote entity established connection but deferred authentication.

Record ID: 4177a6eab980
Client Version: Unknown
Engagement Duration: 0.2s
{
  "id": "4177a6eab980",
  "src_ip": "77.90.185.16",
  "start_time": "2026-05-09T15:03:29.460030Z",
  "end_time": "2026-05-09T15:03:29.632005Z",
  "duration": "0.2",
  "version": null,
  "hassh": null,
  "attempts": [],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": []
}
139.19.117.197
2026-05-09 14:52:54.466594 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (2 distinct queries). Vector identities: admin

Record ID: c2fa23c20873
Client Version: SSH-2.0-Go
Engagement Duration: 10.0s
HASSH Fingerprint: f1e5e9d24e5e345e8745613bde22d532
{
  "id": "c2fa23c20873",
  "src_ip": "139.19.117.197",
  "start_time": "2026-05-09T14:52:54.466594Z",
  "end_time": "2026-05-09T14:53:04.466276Z",
  "duration": "10.0",
  "version": "SSH-2.0-Go",
  "hassh": "f1e5e9d24e5e345e8745613bde22d532",
  "attempts": [
    {
      "user": "admin",
      "pass": null
    },
    {
      "user": "admin",
      "pass": null
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}
87.251.64.176
2026-05-09 14:52:27.048158 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (1 distinct queries). Vector identities: support

Record ID: 11c79ff3e88b
Client Version: SSH-2.0-Go
Engagement Duration: 2.2s
HASSH Fingerprint: eff4c24daffc8532c160e86e5f006e53
{
  "id": "11c79ff3e88b",
  "src_ip": "87.251.64.176",
  "start_time": "2026-05-09T14:52:27.048158Z",
  "end_time": "2026-05-09T14:52:29.233203Z",
  "duration": "2.2",
  "version": "SSH-2.0-Go",
  "hassh": "eff4c24daffc8532c160e86e5f006e53",
  "attempts": [
    {
      "user": "support",
      "pass": "support"
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}
87.251.64.176
2026-05-09 14:48:59.330962 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (1 distinct queries). Vector identities: support

Record ID: ad654fa16631
Client Version: SSH-2.0-Go
Engagement Duration: 2.1s
HASSH Fingerprint: eff4c24daffc8532c160e86e5f006e53
{
  "id": "ad654fa16631",
  "src_ip": "87.251.64.176",
  "start_time": "2026-05-09T14:48:59.330962Z",
  "end_time": "2026-05-09T14:49:01.404913Z",
  "duration": "2.1",
  "version": "SSH-2.0-Go",
  "hassh": "eff4c24daffc8532c160e86e5f006e53",
  "attempts": [
    {
      "user": "support",
      "pass": "support"
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}
2.57.121.25
2026-05-09 14:46:28.078343 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (5 distinct queries). Vector identities: user

Record ID: 608038cef61a
Client Version: SSH-2.0-libssh2_1.9.0
Engagement Duration: 6.8s
HASSH Fingerprint: 57446c12547a668110aa237e5965e374
{
  "id": "608038cef61a",
  "src_ip": "2.57.121.25",
  "start_time": "2026-05-09T14:46:28.078343Z",
  "end_time": "2026-05-09T14:46:34.844998Z",
  "duration": "6.8",
  "version": "SSH-2.0-libssh2_1.9.0",
  "hassh": "57446c12547a668110aa237e5965e374",
  "attempts": [
    {
      "user": "user",
      "pass": "23071996"
    },
    {
      "user": "user",
      "pass": "23071978"
    },
    {
      "user": "user",
      "pass": "230689"
    },
    {
      "user": "user",
      "pass": "23061993"
    },
    {
      "user": "user",
      "pass": "23061978"
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}
87.251.64.176
2026-05-09 14:45:04.332154 UTC
FAILED LOGIN SCORE: 0

Unauthorized authentication attempt escalated. Dictionary traversal detected (1 distinct queries). Vector identities: support

Record ID: 2795363aed80
Client Version: SSH-2.0-Go
Engagement Duration: 1.9s
HASSH Fingerprint: eff4c24daffc8532c160e86e5f006e53
{
  "id": "2795363aed80",
  "src_ip": "87.251.64.176",
  "start_time": "2026-05-09T14:45:04.332154Z",
  "end_time": "2026-05-09T14:45:06.224488Z",
  "duration": "1.9",
  "version": "SSH-2.0-Go",
  "hassh": "eff4c24daffc8532c160e86e5f006e53",
  "attempts": [
    {
      "user": "support",
      "pass": "support"
    }
  ],
  "success_login": false,
  "success_credential": null,
  "commands": [],
  "detailed_commands": [],
  "failed_commands": [],
  "score": 0,
  "tags": [
    "FAILED LOGIN"
  ]
}