TROYANOSYVIRUS
Active ThreatMEDIUM

220.92.117.221

Country of Origin🇰🇷 South Korea
First Detection3/19/2026
Last Activity3/28/2026
ISPKorea Telecom
🎯
15,838
Total Attacks
🔌
2
Ports
📡
1
Attack Types
🦠
1
Malware

Geolocation

Country
🇰🇷 South Korea
City
Changwon
ASN
AS4766
ISP
Korea Telecom

Attack Types

ssh_telnet_honeypot

Attacked Ports

2223

Associated Malware

Attempted Credentials

🔐test/test
7x
🔐root/111111
7x
🔐root/Password123
6x
🔐user/123456
6x
🔐root/1234
5x
🔐root/qwerty
5x
🔐root/123
5x
🔐user/1234
5x
🔐root/Pass1234
5x
🔐root/Pass123
5x
🔐temp/temp
5x
🔐user/12345
5x
🔐root/Password1234567
4x
🔐root/ubuntu123456
4x
🔐root/qwerty123456789
4x

Executed Commands

$uname -a13x

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Ports
44338083808480858091
CPEs
cpe:/a:f5:nginx:1.29.4

Risk Assessment

55
/100
LowMediumHighCritical