Loading threats
Invokes /usr/.work/work32 with two positional arguments, where the first is root and the second is a password-like string. The command itself does not reveal the binary’s internal behavior, only that it is executed with credential-shaped arguments.
| IP Address | Risk | Events | Sessions | Country | ASN | Last Seen |
|---|---|---|---|---|---|---|
| 101.126.4.240 | 62% | 248 | 163 | 🇨🇳 CN | AS137718 | 2026-03-28 |
| 103.47.100.34 | 61% | 192 | 25 | 🇸🇬 SG | AS38136 | 2026-03-05 |
| 101.126.4.215 | 58% | 150 | 107 | 🇨🇳 CN | AS137718 | 2026-03-26 |
| 36.111.34.233 | 58% | 130 | 12 | 🇨🇳 CN | AS58466 | 2026-02-25 |
| 114.55.232.178 | 57% | 120 | 13 | 🇨🇳 CN | AS37963 | 2026-03-06 |
| 194.163.166.224 | 56% | 95 | 31 | 🇫🇷 FR | AS51167 | 2026-03-03 |
| 47.76.229.36 | 57% | 77 | 12 | 🇭🇰 HK | AS45102 | 2026-03-12 |
| 5.182.17.111 | 53% | 69 | 14 | 🇫🇷 FR | AS51167 | 2026-03-09 |
| 8.218.231.192 | 53% | 68 | 4 | 🇭🇰 HK | AS45102 | 2026-02-26 |
| 8.138.156.180 | 40% | 36 | 8 | 🇨🇳 CN | AS37963 | 2026-03-05 |
| 123.172.51.245 | 51% | 25 | 25 | 🇨🇳 CN | AS4134 | 2026-03-04 |
| 61.50.119.110 | 41% | 22 | 22 | 🇨🇳 CN | AS4808 | 2026-03-16 |
| 47.243.35.191 | 41% | 19 | 4 | 🇭🇰 HK | AS45102 | 2026-03-01 |
| 43.252.230.112 | 44% | 18 | 18 | 🇭🇰 HK | AS55933 | 2026-03-25 |
| 222.128.21.25 | 60% | 17 | 17 | 🇨🇳 CN | AS4808 | 2026-03-19 |
| 94.56.40.180 | 57% | 14 | 14 | 🇦🇪 AE | AS5384 | 2026-03-27 |
| 61.240.137.69 | 50% | 12 | 12 | 🇨🇳 CN | AS4837 | 2026-02-26 |
| 167.172.89.117 | 72% | 9 | 9 | 🇸🇬 SG | AS14061 | 2026-03-12 |
| 129.232.22.147 | 71% | 9 | 9 | 🇱🇸 LS | AS33567 | 2026-03-12 |
| 47.239.22.88 | 51% | 9 | 9 | 🇭🇰 HK | AS45102 | 2026-03-24 |