TROYANOSYVIRUS
Ameaca AtivaALTO

103.49.239.252

Pais de Origem🇮🇩 Indonesia
Primeira Deteccao28/02/2026
Ultima Atividade18/03/2026
ISPPT Cloud Hosting Indonesia
🎯
617
Ataques Totais
🔌
1
Portas
📡
1
Tipos de Ataque
🦠
29
Malware

Geolocalizacao

Pais
🇮🇩 Indonesia
Cidade
Desconhecida
ASN
AS136052
ISP
PT Cloud Hosting Indonesia

Tipos de Ataque

ssh_telnet_honeypot

Portas Atacadas

22

Malware Associado

Credenciais Tentadas

🔐345gs5662d34/345gs5662d34
5x
🔐root/3245gs5662d34
2x
🔐grid/3245gs5662d34
1x
🔐newuser/12345678
1x
🔐grid/12345
1x
🔐odoo/odoo123!
1x
🔐minioadmin/Minioadmin123!
1x
🔐yujie/yujie123!
1x
🔐myuser/Myuser123!
1x
🔐excel/password
1x
🔐controlm/controlmpass
1x
🔐test001/Test001123
1x
🔐andrei/12345678
1x
🔐socksuser/12345
1x
🔐ct/ctpass
1x

Comandos Executados

$w5x
$Enter new UNIX password:5x
$lockr -ia .ssh5x
$whoami5x
$cat /proc/cpuinfo | grep name | head -n 1 | awk '{print $4,$5,$6,$7,$8,$9;}'5x
$free -m | grep Mem | awk '{print $2 ,$3, $4, $5, $6, $7}'5x
$cd ~; chattr -ia .ssh; lockr -ia .ssh4x
$uname -a4x
$crontab -l4x
$cat /proc/cpuinfo | grep model | grep name | wc -l4x

Exposicao Shodan InternetDBShodan

Dados InternetDB, nao em tempo real

Portas
22
Hostnames
ip103-49-239-252.cloudhost.web.id
CPEs
cpe:/o:canonical:ubuntu_linuxcpe:/a:openbsd:openssh:9.6p1

Avaliacao de Risco

65
/100
BaixoMedioAltoCritico