TROYANOSYVIRUS
Active ThreatLOW

190.117.204.18

Country of Origin🇵🇪 PE
First Detection3/30/2026
Last Activity3/30/2026
ISPAmerica Movil Peru S.A.C.
🎯
24
Total Attacks
🔌
1
Ports
📡
1
Attack Types
🦠
1
Malware

Geolocation

Country
🇵🇪 PE
City
Unknown
ASN
AS12252
ISP
America Movil Peru S.A.C.

Attack Types

ssh_telnet_honeypot

Attacked Ports

23

Associated Malware

Attempted Credentials

🔐root/1234567890
1x
🔐root/123123
1x
🔐root/GM8182
1x
🔐admin/pass
1x
🔐root/1234
1x

Executed Commands

$q2x
$shell2x
$system2x
$dd bs=52 count=1 if=.s || cat .s || while read i; do echo $i; done < .s1x
$sh1x
$cat /proc/mounts; /bin/busybox TNKPZ1x
$/bin/busybox TNKPZ1x
$tftp; wget; /bin/busybox TNKPZ1x
$enable1x
$while read i1x

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Ports
8089
Hostnames
mail.sinersa.com.pesinersa.com.pe

Risk Assessment

25
/100
LowMediumHighCritical