TROYANOSYVIRUS
Active ThreatMEDIUM

79.116.193.26

Country of Origin🇪🇸 Spain
First Detection3/17/2026
Last Activity3/17/2026
ISPDigi Spain Telecom S.A
🎯
312
Total Attacks
🔌
1
Ports
📡
1
Attack Types
🦠
40
Malware

Geolocation

Country
🇪🇸 Spain
City
Madrid
ASN
AS57269
ISP
Digi Spain Telecom S.A

Attack Types

ssh_telnet_honeypot

Attacked Ports

22

Associated Malware

Executed Commands

$umount /mnt 2 > /dev/null2x
$ls /dev/2x
$dd if=/dev/sda1 bs=512 count=1 2 > /dev/null | strings1x
$ls /dev/vd*1x
$lsblk1x
$ls -la /dev/disk/by-uuid/ && echo '---' && ls /dev/ | grep -E '^(sd|vd|xvd|nbd)'1x
$mount | grep sda5; echo '---'; ls /mnt/ 2>/dev/null1x
$mount | grep sda5 && ls /mnt/1x
$sfdisk -l /dev/sda1x
$cat /proc/partitions; echo ===; blockdev --getsize64 /dev/sda 2>/dev/null; blockdev --getsize64 /dev/sda1 2>/dev/null; blockdev --getsize64 /dev/sda2 2>/dev/null; blockdev --getsize64 /dev/sda5 2>/dev/null1x

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Ports
2000
Hostnames
79-116-193-26.digimobil.es

Risk Assessment

55
/100
LowMediumHighCritical