TROYANOSYVIRUS
Active ThreatLOW

222.165.237.58

Country of Origin🇮🇩 Indonesia
First Detection5/1/2026
Last Activity5/1/2026
ISPPT NettoCyber Indonesia
🎯
23
Total Attacks
🔌
1
Ports
📡
1
Attack Types
🦠
1
Malware

Geolocation

Country
🇮🇩 Indonesia
City
Tangerang
ASN
AS24207
ISP
PT NettoCyber Indonesia

Attack Types

ssh_telnet_honeypot

Attacked Ports

23

Associated Malware

Attempted Credentials

🔐admin/12345
1x
🔐666666/666666
1x
🔐Admin/5up
1x
🔐root/oelinux123
1x

Executed Commands

$system2x
$q2x
$shell2x
$cd /dev/shm; cat .s || cp /bin/echo .s; /bin/busybox YQQNV1x
$dd bs=52 count=1 if=.s || cat .s || while read i; do echo $i; done < .s1x
$sh1x
$while read i1x
$cat /proc/mounts; /bin/busybox YQQNV1x
$enable1x
$/bin/busybox YQQNV1x

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Ports
5542000
Hostnames
ip-58-237-static.velo.net.id

Risk Assessment

25
/100
LowMediumHighCritical