TROYANOSYVIRUS
Active ThreatLOW

95.221.209.120

Country of Origin🇷🇺 Russia
First Detection3/19/2026
Last Activity3/19/2026
ISPPJSC MegaFon
🎯
21
Total Attacks
🔌
1
Ports
📡
1
Attack Types
🦠
1
Malware

Geolocation

Country
🇷🇺 Russia
City
Unknown
ASN
AS12714
ISP
PJSC MegaFon

Attack Types

ssh_telnet_honeypot

Attacked Ports

23

Associated Malware

Attempted Credentials

🔐Administrator/admin
1x
🔐admin/1234
1x

Executed Commands

$q2x
$shell2x
$system2x
$dd bs=52 count=1 if=.s || cat .s || while read i; do echo $i; done < .s1x
$sh1x
$cat /proc/mounts; /bin/busybox AIIVU1x
$cd /dev/shm; cat .s || cp /bin/echo .s; /bin/busybox AIIVU1x
$while read i1x
$enable1x
$/bin/busybox AIIVU1x

Risk Assessment

25
/100
LowMediumHighCritical