TROYANOSYVIRUS
Active Threat β€’ LOW

159.89.239.6

First Detection4/7/2026
Last Activity4/7/2026
ISPDigitalOcean, LLC
🎯
24
Total Attacks
πŸ”Œ
1
Ports
πŸ“‘
1
Attack Types
🦠
2
Malware

Geolocation

Country
πŸ‡ΊπŸ‡Έ United States
City
North Bergen
ASN
AS14061
ISP
DigitalOcean, LLC

Attack Types

ssh_telnet_honeypot

Attacked Ports

22

Associated Malware

Attempted Credentials

πŸ”root/ubuntu
1x
πŸ”root/linux
1x
πŸ”root/debian
1x
πŸ”root/centos
1x

Executed Commands

$chmod +x ./.5296872379564260506/sshd;nohup ./.5296872379564260506/sshd 13.201.2.187 222.186.20.164 178.160.228.51 13.114.11.102 157.137.214.146 47.85.14.117 118.68.136.174 43.207.229.208 45.55.91.50 50.7.53.13 56.155.140.61 45.194.91.139 114.218.57.21 112.217.86.2 222.223.177.118 170.150.255.26 123.54.197.60 45.67.221.216 81.177.215.21 135.136.181.238 13.49.77.151 143.198.53.1 120.48.139.244 117.173.221.93 16.16.77.239 101.69.132.194 43.135.5.118 36.65.80.126 142.93.71.3 154.81.15.179 221.202.181x

Risk Assessment

25
/100
LowMediumHighCritical