TROYANOSYVIRUS
Active ThreatMEDIUM

165.232.67.97

Country of Origin🇩🇪 Germany
First Detection4/7/2026
Last Activity4/8/2026
ISPDigitalOcean, LLC
🎯
59
Total Attacks
🔌
3
Ports
📡
2
Attack Types
🦠
1
Malware

Geolocation

Country
🇩🇪 Germany
City
Frankfurt am Main
ASN
AS14061
ISP
DigitalOcean, LLC

Attack Types

ssh_telnet_honeypot
tcp_trap

Attacked Ports

22238500

Associated Malware

Attempted Credentials

🔐Call-ID: 50000/CSeq: 42 OPTIONS
1x
🔐Max-Forwards: 70/Content-Length: 0
1x
🔐Contact: <sip:nm@nm>/Accept: application/sdp
1x
🔐From: <sip:nm@nm>;tag=root/To: <sip:nm2@nm2>
1x
🔐OPTIONS / HTTP/1.0/(empty)
1x
🔐GET / HTTP/1.0/(empty)
1x
🔐OPTIONS / RTSP/1.0/(empty)
1x
🔐OPTIONS sip:nm SIP/2.0/Via: SIP/2.0/TCP nm;branch=foo
1x

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Ports
22
CPEs
cpe:/o:debian:debian_linuxcpe:/a:openbsd:openssh:9.2p1cpe:/o:linux:linux_kernel

Risk Assessment

55
/100
LowMediumHighCritical