IP Address: 103.91.211.242Previously Malicious

Weekly Summary

Browse or download a weekly review of our cyber threat intelligence data and gain more insight to help protect your network

Top Threats

Cyber Threat Intelligence

Discover Malicious IPs and Domains with Guardicore Cyber Threat Feed

IP Address:
103.91.211.242​
Previously Malicious

This IP address attempted an attack on a machine protected by Guardicore Centra

Threat Information

Role

Attacker

Services Targeted

SSH

Tags

Download File 23 Shell Commands IDS - A Network Trojan was detected Service Stop Package Install Access Suspicious Domain Service Configuration HTTP Download and Allow Execution Service Deletion DNS Query SSH Outgoing Connection Log Tampering Download Operation Successful SSH Login Service Creation Download and Execute

Connect Back Servers

ip-91-121-2.eu ip-37-59-44.eu ip-37-187-154.eu pool.minexmr.com ip-37-59-43.eu your-server.de

37.59.43.136 37.59.44.193 78.46.89.102 58.218.66.168 106.14.42.35 78.46.91.134 37.187.154.79 115.231.163.63 37.59.44.93 176.9.2.144 91.121.2.76

Basic Information

IP Address

103.91.211.242

Domain

-

ISP

Shandong eshinton Network Technology Co.

Country

China

WHOIS

Created Date

-

Updated Date

-

Organization

-

First seen in Guardicore Centra

2019-02-13

Last seen in Guardicore Centra

2019-03-02

What is Guardicore Centra
Guardicore Centra is a data center and cloud security solution that protects the organization's core assets, using flexible, quickly deployed and easy to understand micro-segmentation controls. Centra generates in-context security incidents, with details on attacker tools and techniques, that help IR teams prioritize incident investigation and reduce dwell time. Learn More

Attack Flow

A user logged in using SSH with the following credentials: root / **** - Authentication policy: White List

Successful SSH Login

Service iptables was stopped 2 times

Service Stop

A possibly malicious Package Install was detected

Package Install Download Operation

A possibly malicious Download Operation was detected 2 times

Package Install Download Operation

Process /usr/bin/wget generated outgoing network traffic to: 106.14.42.35:9789 2 times

Outgoing Connection

The file /etc/libstdci was downloaded and executed 1458 times

Download and Execute

Service K01libstdci was created

Service Creation

Service S02libstdci was created

Service Creation

Service libstdci was created

Service Creation

The file /etc/rc.local was downloaded and granted execution privileges

Download and Allow Execution

The file /etc/rc.local was downloaded and granted execution privileges

Download and Allow Execution

The file /tmp/systemxlv was downloaded and executed 637 times

Download and Execute

Process /tmp/systemxlv attempted to access domains: pool.minexmr.com 58 times

DNS Query

Process /tmp/systemxlv generated outgoing network traffic to: your-server.de:80

Outgoing Connection

The file /etc/ceurnadi was downloaded and granted execution privileges

Download and Allow Execution

Process /tmp/systemxlv generated outgoing network traffic to: ip-37-59-44.eu:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-59-44.eu

DNS Query Access Suspicious Domain Outgoing Connection

History File Tampering detected from /bin/bash 2 times

Log Tampering

Process /tmp/systemxlv generated outgoing network traffic to: ip-91-121-2.eu:80 2 times

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-91-121-2.eu 2 times

DNS Query Access Suspicious Domain Outgoing Connection

The file /usr/bin/pgrep was downloaded and executed 5 times

Download and Execute

The file /usr/local/bin/dash was downloaded and executed 51 times

Download and Execute

Log File Tampering detected from /bin/bash on the following logs: /var/log/wtmp

Log Tampering

IDS detected A Network Trojan was detected : DNS request for Monero mining pool

IDS - A Network Trojan was detected

Process /tmp/systemxlv generated outgoing network traffic to: ip-37-59-44.eu:80 2 times

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-59-44.eu 2 times

Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: ip-91-121-2.eu:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-91-121-2.eu

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: your-server.de:80

Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: ip-37-187-154.eu:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-187-154.eu

Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: ip-37-59-44.eu:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-59-44.eu

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: ip-37-59-43.eu:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-59-43.eu

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: ip-37-59-44.eu:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-59-44.eu

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: your-server.de:80

Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: ip-37-187-154.eu:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-187-154.eu

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: ip-91-121-2.eu:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-91-121-2.eu

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: ip-37-187-154.eu:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-187-154.eu 3 times

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: your-server.de:80 3 times

Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: ip-37-187-154.eu:80 2 times

Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: ip-37-59-44.eu:80 3 times

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-59-44.eu 3 times

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: your-server.de:80

Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: ip-91-121-2.eu:80 2 times

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-91-121-2.eu 2 times

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: your-server.de:80

Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: ip-37-187-154.eu:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-187-154.eu

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: ip-37-59-44.eu:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-59-44.eu 6 times

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: your-server.de:80

Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: ip-37-59-44.eu:80 2 times

Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: your-server.de:80

Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: ip-37-59-44.eu:80

Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: your-server.de:80

Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: ip-37-59-44.eu:80 2 times

Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: ip-37-187-154.eu:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-187-154.eu

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: ip-91-121-2.eu:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-91-121-2.eu 2 times

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 91.121.2.76:80

Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 37.187.154.79:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-187-154.eu

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 37.59.43.136:80 2 times

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-59-43.eu 2 times

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 37.187.154.79:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-187-154.eu

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 37.59.43.136:80 3 times

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-59-43.eu 3 times

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 91.121.2.76:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-91-121-2.eu

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 78.46.89.102:80

Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 37.59.43.136:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-59-43.eu

Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 91.121.2.76:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-91-121-2.eu

Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 37.59.43.136:80 2 times

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-59-43.eu 2 times

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 78.46.89.102:80 4 times

Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 37.59.44.193:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-59-44.eu

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 37.187.154.79:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-187-154.eu

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 37.59.44.193:80 2 times

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-59-44.eu 2 times

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 176.9.2.144:80 2 times

Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 37.59.43.136:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-59-43.eu

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 176.9.2.144:80

Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 91.121.2.76:80 2 times

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-91-121-2.eu 2 times

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 37.59.44.193:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-59-44.eu

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 37.187.154.79:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-187-154.eu

Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 37.59.44.193:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-59-44.eu

Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 37.187.154.79:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-187-154.eu

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 176.9.2.144:80

Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 78.46.89.102:80

Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 176.9.2.144:80 2 times

Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 37.59.44.93:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-59-44.eu

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 37.187.154.79:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-187-154.eu

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 37.59.44.93:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-59-44.eu

DNS Query Access Suspicious Domain Outgoing Connection

Process /tmp/systemxlv generated outgoing network traffic to: 37.59.43.136:80 3 times

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-59-43.eu 3 times

DNS Query Access Suspicious Domain Outgoing Connection

Connection was closed due to timeout

Process /tmp/systemxlv generated outgoing network traffic to: 37.59.44.193:80

Outgoing Connection

Process /tmp/systemxlv attempted to access suspicious domains: ip-37-59-44.eu

DNS Query Access Suspicious Domain Outgoing Connection

Associated Files

/etc/sedzksxtH

SHA256: bb32aeed4f6e2a1f5c8f0046658dd243954f07671e6757e0bfd77b937394b5fc

233 bytes

/etc/sedzsP6Dm

SHA256: 74df9dbb0e2d9d9aa32c29b2c11a22617fccc0084356c9b1cc66ebedcd11ef26

271 bytes

/etc/ceurnadi

SHA256: 28df5b54a1618038a29340d88f32c398da4e19c8ea197258cc4a3d210c95159d

2057 bytes

/tmp/systemxlv

SHA256: 93db2ccff25c6a1d027ca0dbcc3e9478bcb113ae4d036011f772cfa6a4bd4853

629120 bytes

/etc/libstdci

SHA256: 6f4d2a05411930fed3f156b133e942c98fca3fb6e39bcd42c8f2ed212037565e

1166228 bytes

/etc/sedr7W0b6

SHA256: 2f6c2c68348aa2ebd0b2b7d60c17a222d6f3c2433b45ad4a76f1820fc027c435

253 bytes

/etc/libstdci

SHA256: ac41b5f7317d0454def1de71c3d17ec2c619ded42a788ca98fb7753a87fa45a8

925064 bytes

/etc/libstdci

SHA256: 0bfedd7f726218378eb12885e4476defc0ce5285972818fe00f85cb62bffbf7a

1166228 bytes

Oops! - Do you see your IP here? Contact us at labs@guardicore.com to remove it from the Threat Intelligence data.

IP Address: 103.91.211.242​Previously Malicious