IP Address: 220.170.144.13Previously Malicious
Browse or download a weekly review of our cyber threat intelligence data and gain more insight to help protect your network
IP Address:
220.170.144.13
Previously Malicious
This IP address attempted an attack on a machine protected by Guardicore Centra
Role |
Attacker, Scanner |
Services Targeted |
SSH |
Tags |
Outgoing Connection Successful SSH Login SSH Access Suspicious Domain New SSH Key Download and Execute |
Associated Attack Servers |
hi-tech.com.eg haleyorapower.co.id opendns.com one.one 117.73.13.229 59.20.175.136 1.1.1.1 103.130.215.132 67.205.168.20 122.51.27.35 208.67.222.222 202.162.221.174 49.232.160.96 47.244.8.87 106.12.34.149 58.221.72.240 122.51.217.125 154.219.1.139 47.105.194.197 |
IP Address |
220.170.144.13 |
|
Domain |
- |
|
ISP |
China Telecom |
|
Country |
China |
|
WHOIS |
Created Date |
- |
Updated Date |
- |
|
Organization |
- |
First seen in Guardicore Centra |
2020-04-20 |
Last seen in Guardicore Centra |
2020-04-24 |
What is Guardicore CentraGuardicore Centra is a data center and cloud security solution that protects the organization's core assets, using flexible, quickly deployed and easy to understand micro-segmentation controls. Centra generates in-context security incidents, with details on attacker tools and techniques, that help IR teams prioritize incident investigation and reduce dwell time. Learn More
A user logged in using SSH with the following credentials: root / ****** - Authentication policy: Reached Max Attempts |
Successful SSH Login |
The file /usr/bin/ichekk was downloaded and executed 44 times |
Download and Execute |
Process /usr/bin/ichekk generated outgoing network traffic to: 1.1.1.1:53, 103.130.215.132:45304, 106.12.34.149:43650, 117.73.13.229:46712, 122.51.217.125:34933, 122.51.27.35:45907, 154.219.1.139:53984, 202.162.221.174:35415, 208.67.222.222:443, 47.105.194.197:42140, 47.244.8.87:33439, 49.232.160.96:35920, 58.221.72.240:43740, 59.20.175.136:51557 and 67.205.168.20:8000 |
Outgoing Connection |
Process /usr/bin/ichekk attempted to access suspicious domains: haleyorapower.co.id, hi-tech.com.eg and one.one |
Access Suspicious Domain Outgoing Connection |
Connection was closed due to timeout |
|
An attempt to download /root/.ssh/authorized_keys was made 25 times |
New SSH Key |
IP Address: 220.170.144.13Previously Malicious