TROYANOSYVIRUS
Active Threat β€’ CRITICAL

143.198.171.196

First Detection4/1/2026
Last Activity4/2/2026
ISPDigitalOcean, LLC
🎯
123
Total Attacks
πŸ”Œ
85
Ports
πŸ“‘
14
Attack Types
🦠
1
Malware

Geolocation

Country
πŸ‡ΊπŸ‡Έ United States
City
North Bergen
ASN
AS14061
ISP
DigitalOcean, LLC

Attack Types

ssh_telnet_honeypot
yaml_exploit_honeypot
voip_honeypot
printer_honeypot
redis_honeypot
elasticsearch_honeypot
adb_honeypot
malware_capture

Attacked Ports

21222380814456311433172318202011201824042829289130003288330633373453+65

Associated Malware

Attempted Credentials

πŸ”Accept-Language: ar,en-US;q=0.9,en;q=0.8/Host: 146.59.94.170:23
1x
πŸ”Connection: TE, close/Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
1x
πŸ”GET / HTTP/1.1/TE: deflate,gzip;q=0.3
1x

Executed Commands

$KHTML, like Gecko2x
$User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.45 Safari/537.361x
$Chrome/96.0.4664.45 Safari/537.361x
$Windows NT 10.0 ; Win64 ; x641x
$Windows NT 10.01x
$Win641x
$x641x

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Risk Assessment

85
/100
LowMediumHighCritical