Loading threats
Automated Telnet-based compromise sequence involving CLI escalation, transition into shell access, multi-directory writable path probing (/var, /tmp, /dev, /mnt, /dev/shm, /usr), reconstruction of a binary payload using BusyBox hex-encoded echo commands (with and without newline suppression), retrieval of remote content via wget, execution attempt through a randomly named BusyBox applet, and forced recursive cleanup (rm -rf). The inclusion of an unknown BusyBox applet invocation strongly indicates execution of a staged or randomly named payload rather than standard utility usage. The overall sequence is characteristic of scripted IoT/Linux bot propagation frameworks performing automated deployment.
| IP Address | Risk | Events | Sessions | Country | ASN | Last Seen |
|---|---|---|---|---|---|---|
| 103.93.93.211 | 100% | 142,130 | 10,966 | 🇮🇩 ID | AS141140 | 2026-04-04 |
| 103.93.93.182 | 100% | 92,312 | 6,841 | 🇮🇩 ID | AS141140 | 2026-04-04 |
| 102.212.40.100 | 100% | 57,520 | 3,466 | 🇳🇬 NG | AS329244 | 2026-03-18 |
| 103.13.138.22 | 100% | 31,589 | 2,963 | 🇮🇩 ID | AS150215 | 2026-04-06 |
| 223.123.38.36 | 100% | 27,060 | 1,891 | 🇵🇰 PK |
| AS138423 |
| 2026-04-09 |
| 223.123.38.33 | 100% | 25,206 | 1,627 | 🇵🇰 PK | AS138423 | 2026-04-09 |
| 223.123.43.1 | 100% | 24,399 | 1,536 | 🇵🇰 PK | AS138423 | 2026-04-09 |
| 223.123.43.69 | 100% | 24,122 | 1,617 | 🇵🇰 PK | AS138423 | 2026-04-06 |
| 223.123.43.5 | 100% | 23,845 | 1,991 | 🇵🇰 PK | AS138423 | 2026-04-09 |
| 223.123.43.7 | 100% | 23,720 | 1,623 | 🇵🇰 PK | AS138423 | 2026-04-09 |
| 223.123.38.34 | 100% | 22,723 | 1,804 | 🇵🇰 PK | AS138423 | 2026-04-09 |
| 223.123.38.35 | 100% | 22,330 | 1,756 | 🇵🇰 PK | AS138423 | 2026-04-08 |
| 223.123.38.32 | 100% | 21,858 | 1,836 | 🇵🇰 PK | AS138423 | 2026-04-09 |
| 223.123.43.0 | 100% | 21,657 | 1,639 | 🇵🇰 PK | AS138423 | 2026-04-09 |
| 223.123.43.71 | 100% | 20,214 | 1,514 | 🇵🇰 PK | AS138423 | 2026-04-07 |
| 223.123.43.6 | 100% | 19,108 | 1,495 | 🇵🇰 PK | AS138423 | 2026-04-09 |
| 223.123.43.3 | 100% | 18,677 | 1,823 | 🇵🇰 PK | AS138423 | 2026-04-07 |
| 223.123.43.70 | 100% | 17,254 | 1,533 | 🇵🇰 PK | AS138423 | 2026-04-09 |
| 223.123.38.37 | 100% | 16,394 | 2,093 | 🇵🇰 PK | AS138423 | 2026-04-08 |
| 223.123.43.68 | 100% | 15,993 | 1,553 | 🇵🇰 PK | AS138423 | 2026-04-08 |