TROYANOSYVIRUS
Active ThreatHIGH

103.20.223.56

Country of Origin🇭🇰 Hong Kong
First Detection3/6/2026
Last Activity3/27/2026
ISPCNSERVERS LLC
🎯
727
Total Attacks
🔌
1
Ports
📡
1
Attack Types
🦠
30
Malware

Geolocation

Country
🇭🇰 Hong Kong
City
Unknown
ASN
AS40065
ISP
CNSERVERS LLC

Attack Types

ssh_telnet_honeypot

Attacked Ports

22

Associated Malware

Attempted Credentials

🔐345gs5662d34/345gs5662d34
7x
🔐root/3245gs5662d34
3x
🔐testuser1/Testuser1123
1x
🔐webserver/12345
1x
🔐root/RootPassword
1x
🔐test/qwer1234
1x
🔐robin/123456
1x
🔐root/haha123
1x
🔐user10/User10123
1x
🔐ghostadmin/Ghostadmin123!
1x
🔐root/123QWEqwe@
1x
🔐root/zzz
1x
🔐root/1234rfv
1x
🔐robin/3245gs5662d34
1x
🔐nuxeo/nuxeo123!
1x

Executed Commands

$Enter new UNIX password:8x
$uname -a7x
$cat /proc/cpuinfo | grep name | wc -l7x
$df -h | head -n 2 | awk 'FNR == 2 {print $2;}'7x
$lockr -ia .ssh7x
$w6x
$crontab -l6x
$cat /proc/cpuinfo | grep model | grep name | wc -l6x
$which ls6x
$lscpu | grep Model6x

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Ports
123
CPEs
cpe:/a:ntp:ntp:3

Risk Assessment

65
/100
LowMediumHighCritical