This IP address has been reported a total of
22
times from
11 distinct
sources.
38.148.92.89 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 11
reports;
Germany
with 5
reports;
Korea (the Republic of)
with 3
reports.
The most common categories in these recent reports were:
Brute-Force
18
times;
SSH
17
times;
Hacking
7
times;
Exploited Host
4
times;
Port Scan
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Observed 2 SSH sessions from SSH-2.0-Go using admin/123456. Activity focused on Linux persistence an ...
show moreObserved 2 SSH sessions from SSH-2.0-Go using admin/123456. Activity focused on Linux persistence and cleanup: checked crontab, then added an @reboot cron entry to run /dev/shm/w.sh with quoted args. The shell searched for writable locations and selected /dev/shm, /tmp, /var/run, /mnt, /root, and / as fallback paths. It created /dev/shm/w.sh and made it executable, and attempted to write files named astats and kstats in writable directories. Host reconnaissance included cat /proc/cpuinfo | grep processor | wc -l and ps commands to list top CPU processes and count matching astats/kstats processes. Anti-forensics commands removed shell history and log files, including .bash_history, /var/run/utmp, /var/run/wtmp, /var/log/lastlog, /home/yum.log, /var/log/wtmp, and /var/log/secure. No downloads, port forwards, or lateral movement were observed.
show less
Single-source SSH brute-force/login using hadoop/hadoop over SSH-2.0-Go. After access, attacker ran ...
show moreSingle-source SSH brute-force/login using hadoop/hadoop over SSH-2.0-Go. After access, attacker ran basic host recon: uname -a, CPU count via /proc/cpuinfo, and ps -eo pid,pcpu,comm --sort=-pcpu | head -n 10. They searched writable locations with a loop over /dev/shm, /tmp, /var/run, /mnt, /root, / and then moved into /tmp. Persistence was attempted by checking crontab and adding an @reboot entry that references /tmp/w.sh. They also staged creation of /tmp/w.sh with chmod +x, but no file contents, downloads, lateral movement, or successful payload execution were observed.
show less
2026-10-09T01:10:52.258903+00:00 netbird.franssen.xyz sshd-session[1776860]: Failed password for inv ...
show more2026-10-09T01:10:52.258903+00:00 netbird.franssen.xyz sshd-session[1776860]: Failed password for invalid user ubuntu from 38.148.92.89 port 35972 ssh2
2026-10-09T01:10:56.933579+00:00 netbird.franssen.xyz sshd-session[1776891]: Invalid user vps from 38.148.92.89 port 36076
2026-10-09T01:10:57.104623+00:00 netbird.franssen.xyz sshd-session[1776891]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=38.148.92.89
2026-10-09T01:10:58.941416+00:00 netbird.franssen.xyz sshd-session[1776891]: Failed password for invalid user vps from 38.148.92.89 port 36076 ssh2
2026-10-09T01:11:02.953708+00:00 netbird.franssen.xyz sshd-session[1776928]: Invalid user ubuntu from 38.148.92.89 port 36224
...
show less
[Honeypot Report] Malware dropped following SSH intrusion
An automated malware loader attempted to ...
show more[Honeypot Report] Malware dropped following SSH intrusion
An automated malware loader attempted to log in to our emulated SSH service, then obtained shell access and executed commands, and finally delivered an executable payload.
Observed: 2026-10-07 04:57 UTC | 1 session | 27 events | SSH (port 22)
Attack chain:
1. 1 credential attempt: test/123456
2. Shell access obtained; 8 distinct commands executed: cd /dev/shm || cd /tmp || cd /var/run || cd /mnt || cd /root ; uname -a ; sh -c 'for d in /dev/shm /tmp /var/run /mnt /root /; do cd "
3. Malicious script dropped: SHA-256 bc36e729c6463e7120677c0d59b9d793401b320520201043048577d4d94cee28, 1,421 bytes, script (#!/usr/bin/env bash)
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/10/38.148.92.89.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
SSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard ...
show moreSSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard). Read-only capture.
show less
SSH login attempts used admin/TCGA$tI7-m0uO$_ and ftpuser/pC+6Ki@Tn8++7_L over SSH-2.0-Go. After acc ...
show moreSSH login attempts used admin/TCGA$tI7-m0uO$_ and ftpuser/pC+6Ki@Tn8++7_L over SSH-2.0-Go. After access, the actor enumerated CPU/process state with cat /proc/cpuinfo | grep processor | wc -l, ps -eo pid,pcpu,comm --sort=-pcpu | head -n 10, and ps aux | grep astats/kstats. They tested writable locations and stage paths under /dev/shm, /tmp, /var/run, /mnt, /root, and /, then used cat > w.sh, cat > astats, and cat > kstats to drop files in /dev/shm. They attempted persistence by checking crontab and adding an @reboot entry for /dev/shm/w.sh with arguments astats, netai, kstats, and ssh 2 az. They also tried to erase evidence with rm -rf .bash_history, /var/run/utmp, /var/run/wtmp, /var/log/lastlog, /usr/adm/lastlog, /home/yum.log, /var/log/wtmp, and /var/log/secure. No lateral movement was observed.
show less
SSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard ...
show moreSSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard). Read-only capture.
show less
propolis: 38.148.92.89 - 16 event(s) across 1 category since 2026-10-05T20:35:55.901634+00:00, curre ...
show morepropolis: 38.148.92.89 - 16 event(s) across 1 category since 2026-10-05T20:35:55.901634+00:00, current score 80.2
show less