TROYANOSYVIRUS
Active ThreatHIGH

185.93.89.191

Country of Origin🇮🇷 Iran
First Detection3/18/2026
Last Activity4/9/2026
ISPLimited Network LTD
🎯
1,227
Total Attacks
🔌
100
Ports
📡
5
Attack Types
🦠
0
Malware

Geolocation

Country
🇮🇷 Iran
City
Unknown
ASN
AS213790
ISP
Limited Network LTD

Attack Types

adb_honeypot
malware_capture
ics_scada_honeypot
tcp_trap
credential_capture

Attacked Ports

811080108110821083108810891090118013801480158016801688178018882000201620192049+80

Associated Malware

No associated malware

Attempted Credentials

🔐admin/123456
4x
🔐123456/123456
4x
🔐admin/admin
4x
🔐abc/abc
3x
🔐proxy/proxy
3x
🔐111/111
3x
🔐12345/12345
3x
🔐1/1
3x
🔐123/123
2x
🔐888/888
2x
🔐123456789/123456789
2x
🔐root/root
2x
🔐admin/1
1x
🔐user/pass
1x
🔐test/test
1x

ThreatFox Intelabuse.ch

⚠️KNOWN C2 SERVER
Malware Families
elf.systembc
Threat Types
botnet_cc
Confidence: 100%

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Ports
9000
CPEs
cpe:/a:yandex:clickhouse

Risk Assessment

75
/100
LowMediumHighCritical