HoneyMire Hub

Attack #555989 ssh

Captured 2026-08-13 22:31:27Z by Ka on honeypot FR1 ⬜ docker-edge · firmware 0.1.0.

Source186.148.224.83:36678
Target port22
Authenticatedyes
Commands1
Duration8.4s

Session recording

Loading session…

Transcript

Server output and attacker input as captured, line-grain. Malware URLs are obscured until sign-in.

cd ~; chattr -ia .ssh; lockr -ia .ssh
-bash: chattr: command not found
-bash: lockr: command not found

Credentials

Username: ubuntu

Password: 123.com

1 login attempt(s) before disconnect.

Geolocation hub-resolved

🇦🇷Argentina · Buenos Aires · Villa José León Suárez

Grupo in S.A.S · AS64123 DODOLINK INTERNACIONAL SRL · -34.54,-58.59

Network: residential · dodoLink · Cable/DSL/ISP · peeringdb · medium confidence

Behavioral classification

🤖 55% confidence

Automated tool, unknown family — uniform timing but no matched signature.

Command summary

cd ~; chattr -ia .ssh; lockr -ia .ssh

Reported to threat intel

none

HoneyMire Hub · open feed: / · API: /api · docs: /docs · blocklists: /blocklists · about: /about · firmware: github.com/HoneyMire/HoneyMire