TROYANOSYVIRUS
Active ThreatLOW

125.212.244.35

Country of Origin🇻🇳 Vietnam
First Detection4/1/2026
Last Activity4/2/2026
ISPViettel Group
🎯
18
Total Attacks
🔌
1
Ports
📡
1
Attack Types
🦠
1
Malware

Geolocation

Country
🇻🇳 Vietnam
City
Ho Chi Minh City
ASN
AS7552
ISP
Viettel Group

Attack Types

ssh_telnet_honeypot

Attacked Ports

22

Associated Malware

Attempted Credentials

🔐crypto/CryptoNode!@#
1x
🔐developer/Developer!@#2025
1x
🔐test/TestSecure!@#
1x

Executed Commands

$uname -a 2>&1 || echo unknown1x

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Ports
5380123443330610001
Vulnerabilities
CVE-2015-8139CVE-2015-7853CVE-2015-7854CVE-2015-7974CVE-2015-3405CVE-2014-9750CVE-2016-9311CVE-2017-6451CVE-2017-6464CVE-2015-7975CVE-2020-13817CVE-2015-7849CVE-2017-6452CVE-2015-7691CVE-2016-2518CVE-2018-7184CVE-2015-5146CVE-2016-7428CVE-2016-7426CVE-2015-7701
Hostnames
cp.ecommerce-invoice.vn
CPEs
cpe:/a:ntp:ntp:4.2.8:p15cpe:/a:f5:nginxcpe:/a:mariadb:mariadb:10.11.7-MariaDB-1%3a10.11.7%2bmaria%7eubu2204

Risk Assessment

25
/100
LowMediumHighCritical