TROYANOSYVIRUS
Active Threat β€’ MEDIUM

104.194.133.55

First Detection5/9/2026
Last Activity5/9/2026
ISPRouterHosting LLC
🎯
1,862
Total Attacks
πŸ”Œ
1
Ports
πŸ“‘
1
Attack Types
🦠
1
Malware

Geolocation

Country
πŸ‡ΊπŸ‡Έ United States
City
Las Vegas
ASN
AS14956
ISP
RouterHosting LLC

Attack Types

ssh_telnet_honeypot

Attacked Ports

22

Associated Malware

Attempted Credentials

πŸ”frappe/frappe
2x
πŸ”user/user
2x
πŸ”root/Aa123456@
1x
πŸ”root/Aa123123
1x
πŸ”developer/123456
1x
πŸ”elk/elk@123
1x
πŸ”gg/gg
1x
πŸ”root/rock
1x
πŸ”cursor/cursor
1x
πŸ”testuser/123456
1x
πŸ”root/passw0rd
1x
πŸ”test/test!@
1x
πŸ”elasticsearch/elasticsearch
1x
πŸ”aiuser/aiuser
1x
πŸ”root/Admin@123
1x

Executed Commands

$uname -s -v -n -r -m3x

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Ports
3389
Hostnames
55.133.194.104.static.cloudzy.com

Risk Assessment

45
/100
LowMediumHighCritical