Check an IP Address, Domain Name, Subnet, or ASN
77.42.88.138 has a threat confidence score of 100%. This IP address from Finland (AS24940, Hetzner Online GmbH) has been observed in 413 honeypot sessions targeting SSH protocols. Detected attack patterns include ssh full host reconnaissance snapshot, ssh hardened host profiling and shell rc immutability bypass. First observed on March 14, 2026, most recently active March 20, 2026.
Comprehensive post-authentication SSH reconnaissance behavior where an actor performs broad system, network, and environment enumeration in a single session. This includes kernel and OS fingerprinting, CPU and memory inspection, network interface and routing discovery, open port enumeration, process listing, credential file probing, service enumeration, and temporary file write/delete testing. The pattern indicates automated host profiling for capability assessment and potential lateral movement preparation.
Identifies SSH post-auth activity combining resilient multi-source CPU enumeration (explicit /usr/bin/nproc fallback) with removal of the immutable flag from ~/.shellrc via chattr, indicating host profiling followed by shell configuration tampering for persistence preparation.