TROYANOSYVIRUS
Active ThreatHIGH

139.45.211.20

Country of Origin🇰🇿 KZ
First Detection4/24/2026
Last Activity4/24/2026
ISPRETN KZ Ltd
🎯
399
Total Attacks
🔌
3
Ports
📡
2
Attack Types
🦠
1
Malware

Geolocation

Country
🇰🇿 KZ
City
Almaty
ASN
AS44877
ISP
RETN KZ Ltd

Attack Types

ssh_telnet_honeypot
tcp_trap

Attacked Ports

2220222222

Associated Malware

Attempted Credentials

🔐root/SangomaDefaultPassword
8x
🔐systems/vivo@01011
7x
🔐root/helloasterisk
6x
🔐sangoma/Itsemoemo2025@Fuck@allPBX
6x
🔐systems/Itsemoemo2025@Washere2025
6x
🔐systems/Itsemoemo2025@Fuck@allPBX
6x
🔐root/Itsemoemo2025@Fuck@allPBX
5x
🔐pbxsystem/pbx@01011
5x
🔐admin/Itsemoemo2025@Fuck@allPBX
5x
🔐emoss/Itsemoemo2025@Fuck@allPBX
3x
🔐emo/Itsemoemo2025@Washere2025
3x
🔐adminss/Itsemoemo2025@Fuck@allPBX
2x
🔐supportss/Itsemoemo2025@Fuck@allPBX
1x
🔐centos/Itsemoemo2025@Washere2025
1x

Executed Commands

$echo login_success6x

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Risk Assessment

60
/100
LowMediumHighCritical