TROYANOSYVIRUS
Active ThreatLOW

121.146.75.226

Country of Origin🇰🇷 South Korea
First Detection3/31/2026
Last Activity4/3/2026
ISPKorea Telecom
🎯
45
Total Attacks
🔌
1
Ports
📡
1
Attack Types
🦠
2
Malware

Geolocation

Country
🇰🇷 South Korea
City
Changwon
ASN
AS4766
ISP
Korea Telecom

Attack Types

ssh_telnet_honeypot

Attacked Ports

23

Associated Malware

Attempted Credentials

🔐root/jvbzd
1x
🔐root/666666
1x
🔐admin/123456
1x
🔐administrator/1234
1x
🔐root/juantech
1x
🔐admin/54321
1x
🔐root/admin
1x

Executed Commands

$q4x
$shell4x
$system4x
$enable2x
$rm .s; exit2x
$dd bs=52 count=1 if=.s || cat .s || while read i; do echo $i; done < .s2x
$sh2x
$while read i2x
$cat /proc/mounts; /bin/busybox NNZBZ1x
$/bin/busybox CMSEE1x

Risk Assessment

30
/100
LowMediumHighCritical