TROYANOSYVIRUS
Active Threat β€’ HIGH

157.245.115.125

First Detection2/21/2026
Last Activity4/5/2026
ISPDigitalOcean, LLC
🎯
441
Total Attacks
πŸ”Œ
1
Ports
πŸ“‘
1
Attack Types
🦠
3
Malware

Geolocation

Country
πŸ‡ΊπŸ‡Έ United States
City
Clifton
ASN
AS14061
ISP
DigitalOcean, LLC

Attack Types

ssh_telnet_honeypot

Attacked Ports

22

Associated Malware

Attempted Credentials

πŸ”minoxidil4you/minoxidil4you!
8x
πŸ”root/minoxidil4you!
7x
πŸ”admin123/minoxidil4you!
4x
πŸ”userminoxidil4you/minoxidil4you!
4x
πŸ”minoxidil4youweb/minoxidil4you!
4x
πŸ”MINOXIDIL4YOU/minoxidil4you!
4x
πŸ”manager/minoxidil4you!
4x
πŸ”ubuntu/minoxidil4you!
4x
πŸ”support/minoxidil4you!
4x
πŸ”admin/minoxidil4you!
4x
πŸ”noreply/minoxidil4you!
4x
πŸ”hostmaster/minoxidil4you!
4x
πŸ”debian/minoxidil4you!
4x
πŸ”root123/minoxidil4you!
4x
πŸ”administrator/minoxidil4you!
4x

Executed Commands

$uname -a1x
$ls -la /home/ 2>/dev/null | grep -q phil && echo 'phil_found' || echo 'ok'1x
$uname -a 2>&1 || echo unknown1x

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Ports
22804439000
Vulnerabilities
CVE-2024-33662CVE-2021-42650CVE-2024-33661CVE-2022-24961
Hostnames
www.americasober.comamericasober.comamericasober.prod
CPEs
cpe:/a:openbsd:openssh:8.2p1cpe:/a:f5:nginxcpe:/a:angularjs:angular.jscpe:/o:canonical:ubuntu_linuxcpe:/a:portainer:portainer:2.0.0

Risk Assessment

60
/100
LowMediumHighCritical