TROYANOSYVIRUS
Active Threat β€’ MEDIUM

157.245.10.239

First Detection3/30/2026
Last Activity3/31/2026
ISPDigitalOcean, LLC
🎯
515
Total Attacks
πŸ”Œ
1
Ports
πŸ“‘
1
Attack Types
🦠
2
Malware

Geolocation

Country
πŸ‡ΊπŸ‡Έ United States
City
Clifton
ASN
AS14061
ISP
DigitalOcean, LLC

Attack Types

ssh_telnet_honeypot

Attacked Ports

22

Associated Malware

Attempted Credentials

πŸ”user/monkey
2x
πŸ”user/123456789
2x
πŸ”root/12345678
2x
πŸ”user/qwerty
2x
πŸ”user/letmein
2x
πŸ”user/root
2x
πŸ”user/dragon
2x
πŸ”user/password
2x
πŸ”root/123456789
2x
πŸ”user/12345678
2x
πŸ”user/admin
2x
πŸ”root/admin
2x
πŸ”user/welcome
2x
πŸ”root/123456
2x
πŸ”user/123456
2x

Executed Commands

$hostname1x
$pwd1x

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Ports
2280500059006080
Vulnerabilities
CVE-2020-29396CVE-2009-2940CVE-2025-13837CVE-2025-13836CVE-2021-32052CVE-2009-3720CVE-2025-12084CVE-2025-12781CVE-2025-6075
CPEs
cpe:/o:linux:linux_kernelcpe:/a:openbsd:openssh:10.0p2cpe:/a:python:python:3.13.7cpe:/o:canonical:ubuntu_linuxcpe:/a:f5:nginx:1.28.0

Risk Assessment

45
/100
LowMediumHighCritical