TROYANOSYVIRUS
Active ThreatMEDIUM

47.239.240.68

Country of Origin🇭🇰 Hong Kong
First Detection4/27/2026
Last Activity4/29/2026
ISPAlibaba US Technology Co., Ltd.
🎯
913
Total Attacks
🔌
1
Ports
📡
1
Attack Types
🦠
1
Malware

Geolocation

Country
🇭🇰 Hong Kong
City
Hong Kong
ASN
AS45102
ISP
Alibaba US Technology Co., Ltd.

Attack Types

ssh_telnet_honeypot

Attacked Ports

22

Associated Malware

Attempted Credentials

🔐root/eve
2x
🔐gary/gary
2x
🔐flask/flask
2x
🔐claude/claude
2x
🔐root/Huawei123
2x
🔐newuser/newuser
2x
🔐ansible/ansible
2x
🔐root/rootroot
2x
🔐ubnt/ubnt
2x
🔐amir/amir
2x
🔐root/abcd1234
2x
🔐minecraft/password
2x
🔐esuser/123456
2x
🔐rdpuser/123456
2x
🔐docker/docker
2x

Executed Commands

$uname -s -v -n -r -m3x

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Ports
22
CPEs
cpe:/o:linux:linux_kernelcpe:/o:debian:debian_linuxcpe:/a:openbsd:openssh:9.2p1

Risk Assessment

50
/100
LowMediumHighCritical