This IP address has been reported a total of
16
times from
9 distinct
sources.
152.228.235.47 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Observed SSH login with mailadmin/MhS+xYL#-OpmE0@ from SSH-2.0-Go. Post-auth activity attempted to s ...
show moreObserved SSH login with mailadmin/MhS+xYL#-OpmE0@ from SSH-2.0-Go. Post-auth activity attempted to stage and persist a script in /dev/shm: cd "/dev/shm" && if [ ! -f "w.sh" ]; then cat > "w.sh" && chmod +x it, then added an @reboot crontab entry invoking /dev/shm/w.sh with arguments including "astats" "netai" "kstats" "ssh 2 ranges". The session also wrote payloads named astats and kstats to writable paths, checked CPU count via /proc/cpuinfo, listed top CPU processes, and counted running astats/kstats processes. Cleanup/evasion commands removed shell history and logs including .bash_history, utmp, wtmp, lastlog, yum.log, and /var/log/secure. No lateral movement, port forwarding, or file download commands were observed.
show less
[Honeypot Report] Malware dropped following SSH intrusion
An automated malware loader attempted mul ...
show more[Honeypot Report] Malware dropped following SSH intrusion
An automated malware loader attempted multiple logins against our emulated SSH service, then obtained shell access and executed commands, and finally delivered an executable payload.
Observed: 2026-09-26 05:02 to 2026-09-26 05:39 UTC | 2 sessions | 54 events | SSH (port 22)
Attack chain:
1. 2 credential attempts: test/123456, root/123
2. Shell access obtained; 8 distinct commands executed: cd /dev/shm || cd /tmp || cd /var/run || cd /mnt || cd /root ; uname -a ; sh -c 'for d in /dev/shm /tmp /var/run /mnt /root /; do cd "
3. Malicious script dropped: SHA-256 bc36e729c6463e7120677c0d59b9d793401b320520201043048577d4d94cee28, 1,421 bytes, script (#!/usr/bin/env bash)
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/09/152.228.235.47.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
2026-09-25T20:08:09.662671+08:00 *hostname* sshd-session[92190]: Invalid user ubuntu from 152.228.23 ...
show more2026-09-25T20:08:09.662671+08:00 *hostname* sshd-session[92190]: Invalid user ubuntu from 152.228.235.47 port 41064
2026-09-25T20:08:08.792471+08:00 *hostname* sshd-session[92190]: Connection from 152.228.235.47 port 41064 on 10.66.0.230 port 22 rdomain ""
2026-09-25T20:08:09.662671+08:00 *hostname* sshd-session[92190]: Invalid user ubuntu from 152.228.235.47 port 41064
2026-09-25T20:08:10.096702+08:00 *hostname* sshd-session[92194]: Connection from 152.228.235.47 port 41068 on 10.66.0.230 port 22 rdomain ""
2026-09-25T20:08:10.979877+08:00 *hostname* sshd-session[92194]: Invalid user postgres from 152.228.235.47 port 41068
show less
SSH login succeeded with reused credentials mailadmin/mailadmin from SSH-2.0-Go. Session actions sho ...
show moreSSH login succeeded with reused credentials mailadmin/mailadmin from SSH-2.0-Go. Session actions showed container/CPU recon, process enumeration, and multi-path file placement in writable locations. The operator checked processor count and top CPU processes, then searched for specific artifacts named astats and kstats. They wrote files in /dev/shm and attempted to build a launcher in /dev/shm/w.sh, followed by a crontab persistence check/addition targeting @reboot execution of /dev/shm/w.sh with arguments "astats" "netai" "kstats" "ssh 2 ranges". They also issued cleanup commands to remove shell history and log files such as /var/run/utmp, /var/run/wtmp, /var/log/lastlog, /var/log/wtmp, and /var/log/secure. No downloads, port forwards, lateral movement, or malware hashes were observed in the provided activity.
show less
Observed 2 SSH sessions over ~10 seconds using ftpuser/ftpuser from SSH-2.0-Go. The actor ran uname ...
show moreObserved 2 SSH sessions over ~10 seconds using ftpuser/ftpuser from SSH-2.0-Go. The actor ran uname -a, cat /proc/cpuinfo | grep processor | wc -l, ps -eo pid,pcpu,comm --sort=-pcpu | head -n 10, and a shell loop to locate a writable directory (/dev/shm, /tmp, /var/run, /mnt, /root, /). In /tmp, the actor checked for w.sh, created it if missing, and chmod +x'd it. The session then queried crontab -l and appended an @reboot entry referencing /tmp/w.sh with arguments "astats" "netai" "kstats" "ssh 2 ranges". No downloads, dropped artifacts, lateral movement, port forwarding, or other persistence were observed beyond the cron startup entry and /tmp script staging.
show less
2026-09-24T12:10:18.514111+08:00 *hostname* sshd-session[45909]: Invalid user ubuntu from 152.228.23 ...
show more2026-09-24T12:10:18.514111+08:00 *hostname* sshd-session[45909]: Invalid user ubuntu from 152.228.235.47 port 58358
2026-09-24T12:10:18.905422+08:00 *hostname* sshd-session[45911]: Connection from 152.228.235.47 port 58368 on 10.66.0.230 port 22 rdomain ""
2026-09-24T12:10:19.663535+08:00 *hostname* sshd-session[45911]: Invalid user postgres from 152.228.235.47 port 58368
2026-09-24T12:10:21.221166+08:00 *hostname* sshd-session[45915]: Connection from 152.228.235.47 port 50362 on 10.66.0.230 port 22 rdomain ""
2026-09-24T12:10:21.980980+08:00 *hostname* sshd-session[45915]: Invalid user postgres from 152.228.235.47 port 50362
show less
Brute-Force
SSH
Showing 1 to
15
of 16 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ