TROYANOSYVIRUS
Ameaca AtivaBAIXO

195.22.238.211

Pais de Origem🇲🇩 MD
Primeira Deteccao26/04/2026
Ultima Atividade26/04/2026
ISPOrange Moldova S.A.
🎯
21
Ataques Totais
🔌
1
Portas
📡
1
Tipos de Ataque
🦠
1
Malware

Geolocalizacao

Pais
🇲🇩 MD
Cidade
Sîngera
ASN
AS25454
ISP
Orange Moldova S.A.

Tipos de Ataque

ssh_telnet_honeypot

Portas Atacadas

23

Malware Associado

Credenciais Tentadas

🔐service/service
1x
🔐root/1234567890
1x

Comandos Executados

$q2x
$system2x
$shell2x
$cat /proc/mounts; /bin/busybox AAZEM1x
$/bin/busybox AAZEM1x
$dd bs=52 count=1 if=.s || cat .s || while read i; do echo $i; done < .s1x
$cd /dev/shm; cat .s || cp /bin/echo .s; /bin/busybox AAZEM1x
$sh1x
$enable1x
$while read i1x

Exposicao Shodan InternetDBShodan

Dados InternetDB, nao em tempo real

Portas
21231024200082918728
Vulnerabilidades
CVE-2020-20250CVE-2019-3976CVE-2020-20249CVE-2019-3979CVE-2018-7445CVE-2017-20149CVE-2020-20264CVE-2020-20221CVE-2019-16160CVE-2019-13074CVE-2023-32154CVE-2020-20217CVE-2020-20253CVE-2020-20247CVE-2019-3977CVE-2022-45315CVE-2023-30800CVE-2018-1157CVE-2018-1156CVE-2020-20220
Hostnames
mail.arec.md
CPEs
cpe:/o:mikrotik:routeros:6.27

Avaliacao de Risco

25
/100
BaixoMedioAltoCritico