ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 37.220.87.78:25387.

Database Entry


IOC ID:1103291
IOC: 37.220.87.78:25387
IOC Type :ip:port
Threat Type :botnet_cc
Malware: RedLine Stealer
Malware alias:RECORDSTEALER
Confidence Level : Confidence level is high (100%)
ASN:AS207713 GIR-AS
Country:- RU
First seen:2023-04-13 13:14:24 UTC
Last seen:2023-08-01 18:02:11 UTC
UUID:1c6a813c-d9fd-11ed-8380-42010aa4000a
Reporter iamdeadlyz
Reward 5 credits from ThreatFox
Tags:FakeGrinProMiner FakeKOTA MetaWorld
Reference: https://bazaar.abuse.ch/sample/267611a017bb24a4c7b3231f4c5bd2688265fe0c59a30d3ce463a84cd8d7b76a/

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2023-04-13 13:35:16 25abc25a488468887ae9b909116f16841a6be0948c5d2b9240f64be0761653de
2023-04-13 13:35:15 77e2293bdd12781cda3009d2964175748de10f9ea33391f269af12a83ed71864