IP Address: 148.71.61.220Previously Malicious
Browse or download a weekly review of our cyber threat intelligence data and gain more insight to help protect your network
IP Address:
148.71.61.220
Previously Malicious
This IP address attempted an attack on a machine protected by Guardicore Centra
Role |
Attacker, Scanner |
Services Targeted |
SSH |
Tags |
Outgoing Connection Successful SSH Login Download and Execute Access Suspicious Domain New SSH Key SSH |
Associated Attack Servers |
hi-tech.com.eg miami-servers.com opendns.com one.one 111.21.179.94 129.28.189.168 106.75.30.196 122.114.72.127 42.62.6.200 162.252.57.148 1.1.1.1 67.205.168.20 208.67.222.222 111.67.194.253 103.15.226.116 113.79.13.146 111.229.73.125 134.175.103.202 139.129.15.237 |
IP Address |
148.71.61.220 |
|
Domain |
- |
|
ISP |
Vodafone Portugal |
|
Country |
Portugal |
|
WHOIS |
Created Date |
- |
Updated Date |
- |
|
Organization |
- |
First seen in Guardicore Centra |
2020-03-08 |
Last seen in Guardicore Centra |
2020-03-23 |
What is Guardicore CentraGuardicore Centra is a data center and cloud security solution that protects the organization's core assets, using flexible, quickly deployed and easy to understand micro-segmentation controls. Centra generates in-context security incidents, with details on attacker tools and techniques, that help IR teams prioritize incident investigation and reduce dwell time. Learn More
A user logged in using SSH with the following credentials: root / ******** - Authentication policy: White List |
Successful SSH Login |
The file /usr/bin/aniwxc was downloaded and executed 30 times |
Download and Execute |
Process /usr/bin/aniwxc generated outgoing network traffic to: 1.1.1.1:53, 103.15.226.116:33807, 106.75.30.196:44607, 111.21.179.94:44089, 111.229.73.125:40539, 111.67.194.253:36843, 113.79.13.146:33725, 122.114.72.127:43483, 129.28.189.168:34213, 134.175.103.202:46156, 139.129.15.237:44229, 162.252.57.148:37978, 208.67.222.222:443, 42.62.6.200:55454 and 67.205.168.20:8000 |
Outgoing Connection |
Process /usr/bin/aniwxc attempted to access suspicious domains: hi-tech.com.eg, miami-servers.com and one.one |
Access Suspicious Domain Outgoing Connection |
Connection was closed due to timeout |
|
An attempt to download /root/.ssh/authorized_keys was made 25 times |
New SSH Key |
IP Address: 148.71.61.220Previously Malicious