This IP address has been reported a total of
8
times from
4 distinct
sources.
57.131.198.55 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 5
reports;
Germany
with 2
reports;
Finland
with 1
report.
Over the same time period, 57.131.198.55 has changed
country of origin 2 times.
The most common categories in these recent reports were:
Brute-Force
8
times;
SSH
5
times;
Exploited Host
1
time;
Hacking
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Attempted SSH login with ubuntu/ubuntu123 using SSH-2.0-Go. After access, the actor ran cat /etc/pas ...
show moreAttempted SSH login with ubuntu/ubuntu123 using SSH-2.0-Go. After access, the actor ran cat /etc/passwd to enumerate local accounts, passwd to attempt password changes, and uname -a to identify the host kernel and system details. No downloads, persistence, port forwarding, or lateral movement were observed. No artifacts were dropped.
show less
Single SSH login using admin/123456. Attacker ran host recon (uname -a, CPU core count, top processe ...
show moreSingle SSH login using admin/123456. Attacker ran host recon (uname -a, CPU core count, top processes, writable dir check) and staged persistence. Dropped /tmp/w.sh then set an @reboot crontab entry referencing /tmp/w.sh with arguments "astats" "netai" "kstats" "ssh 2 az". Also attempted systemd user persistence by creating ~/.config/systemd/user/watcher-netai.service, reloading the user daemon, and enabling the service. No downloads, payload execution, lateral movement, or additional credentials were observed in this session.
show less
root/root was used to log in over SSH (SSH-2.0-Go) in 2 sessions. Activity included checking CPU cou ...
show moreroot/root was used to log in over SSH (SSH-2.0-Go) in 2 sessions. Activity included checking CPU count and running process listings, then staging persistence in /dev/shm with a shell script named w.sh and a crontab @reboot entry to execute /dev/shm/w.sh "astats" "netai". The actor attempted to create files named astats and kstats in writable locations (/dev/shm, /tmp, /var/run, /mnt, /root, /) and then repeatedly checked for their presence with ps/grep. Commands also removed local traces by deleting shell history and log files including /var/run/utmp, /var/run/wtmp, /var/log/lastlog, /usr/adm/lastlog, /home/yum.log, /var/log/wtmp, and /var/log/secure. No downloads, payload execution, lateral movement, or artifacts were observed beyond the staged filenames w.sh, astats, and kstats.
show less
[Honeypot Report] Malware dropped following SSH intrusion
An automated malware loader attempted to ...
show more[Honeypot Report] Malware dropped following SSH intrusion
An automated malware loader attempted to log in to our emulated SSH service, then obtained shell access and executed commands, and finally delivered an executable payload.
Observed: 2026-10-03 17:34 UTC | 1 session | 27 events | SSH (port 22)
Attack chain:
1. 1 credential attempt: ubuntu/123456
2. Shell access obtained; 8 distinct commands executed: cd /dev/shm || cd /tmp || cd /var/run || cd /mnt || cd /root ; uname -a ; sh -c 'for d in /dev/shm /tmp /var/run /mnt /root /; do cd "
3. Malicious script dropped: SHA-256 bc36e729c6463e7120677c0d59b9d793401b320520201043048577d4d94cee28, 1,421 bytes, script (#!/usr/bin/env bash)
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/10/57.131.198.55.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less