TROYANOSYVIRUS
Active ThreatMEDIUM

164.92.161.29

Country of Origin🇩🇪 Germany
First Detection4/26/2026
Last Activity4/28/2026
ISPDigitalOcean, LLC
🎯
83
Total Attacks
🔌
2
Ports
📡
2
Attack Types
🦠
1
Malware

Geolocation

Country
🇩🇪 Germany
City
Frankfurt am Main
ASN
AS14061
ISP
DigitalOcean, LLC

Attack Types

ssh_telnet_honeypot
malware_capture

Attacked Ports

2123

Associated Malware

Attempted Credentials

🔐Call-ID: 50000/CSeq: 42 OPTIONS
2x
🔐Max-Forwards: 70/Content-Length: 0
2x
🔐Contact: <sip:nm@nm>/Accept: application/sdp
2x
🔐From: <sip:nm@nm>;tag=root/To: <sip:nm2@nm2>
2x
🔐OPTIONS / HTTP/1.0/(empty)
2x
🔐GET / HTTP/1.0/(empty)
2x
🔐OPTIONS / RTSP/1.0/(empty)
2x
🔐OPTIONS sip:nm SIP/2.0/Via: SIP/2.0/TCP nm;branch=foo
2x

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Ports
443
Vulnerabilities
CVE-2023-44487CVE-2021-3618CVE-2025-23419CVE-2021-23017
Hostnames
test.storyjar.fun
CPEs
cpe:/o:canonical:ubuntu_linuxcpe:/o:linux:linux_kernelcpe:/a:f5:nginx:1.18.0

Risk Assessment

50
/100
LowMediumHighCritical