TROYANOSYVIRUS
Active ThreatMEDIUM

158.94.209.131

Country of Origin🇳🇱 Netherlands
First Detection4/2/2026
Last Activity4/3/2026
ISPOmegatech LTD
🎯
3,812
Total Attacks
🔌
1
Ports
📡
1
Attack Types
🦠
1
Malware

Geolocation

Country
🇳🇱 Netherlands
City
Amsterdam
ASN
AS202412
ISP
Omegatech LTD

Attack Types

ssh_telnet_honeypot

Attacked Ports

22

Associated Malware

Attempted Credentials

🔐user/user
4x
🔐frappe/frappe
4x
🔐www/123456
2x
🔐test/test!@
2x
🔐elasticsearch/elasticsearch
2x
🔐aiuser/aiuser
2x
🔐root/root@123
2x
🔐root/p@ssw0rd
2x
🔐admin1/admin1
2x
🔐nexus/nexus
2x
🔐vbox/123456
2x
🔐centos/centos
2x
🔐rancher/rancher
2x
🔐fastuser/fastuser
2x
🔐minecraft/123456
2x

Executed Commands

$uname -s -v -n -r -m4x

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Ports
221351374453389598547001
CPEs
cpe:/o:canonical:ubuntu_linuxcpe:/a:openbsd:openssh:8.9p1

Risk Assessment

45
/100
LowMediumHighCritical