TROYANOSYVIRUS
Active ThreatLOW

138.68.106.123

Country of Origin🇩🇪 Germany
First Detection4/18/2026
Last Activity4/22/2026
ISPDigitalOcean, LLC
🎯
43
Total Attacks
🔌
2
Ports
📡
2
Attack Types
🦠
0
Malware

Geolocation

Country
🇩🇪 Germany
City
Frankfurt am Main
ASN
AS14061
ISP
DigitalOcean, LLC

Attack Types

ssh_telnet_honeypot
tcp_trap

Attacked Ports

222222

Associated Malware

No associated malware

Attempted Credentials

🔐a/a
2x
🔐nil/(empty)
2x
🔐root/root
1x
🔐orangepi/orangepi
1x
🔐admin/admin
1x

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Ports
21222325804455132121222254326667800988889090
Vulnerabilities
CVE-2007-4723CVE-2010-4478CVE-2019-18217CVE-2011-5000CVE-2021-36368CVE-2016-10012CVE-2009-0543CVE-2019-6111CVE-2026-35414CVE-2020-15778CVE-2011-1176CVE-2010-3867CVE-2008-7265CVE-2012-0814CVE-2009-2299CVE-2007-2768CVE-2015-5352CVE-2012-4001CVE-2018-20685CVE-2011-4327
CPEs
cpe:/a:openbsd:openssh:8.9p1cpe:/a:postgresql:postgresql:8.3cpe:/a:apache:tomcatcpe:/a:openbsd:openssh:4.7p1cpe:/a:postfix:postfixcpe:/o:canonical:ubuntu_linuxcpe:/o:linux:linux_kernelcpe:/a:apache:http_server:2.4.66cpe:/a:proftpd:proftpd:1.3.1cpe:/a:f5:nginx:1.25.4cpe:/a:php:php:8.5.2cpe:/a:f5:nginx:1.29.2cpe:/o:debian:debian_linux

Risk Assessment

32
/100
LowMediumHighCritical