ThreatFox IOC Database
You are viewing the ThreatFox database entry for url http://77.105.147.158:5001/upload/.
Database Entry
This IOC expired
This IOC is an old IOC and hence has expired on 2026-09-15 08:57:25 UTC. We therefore refrain from exporting it into our datasets. As a result, this database entry is purely informational and has no impact.
| IOC ID: | 1136661 |
|---|---|
| IOC: | http://77.105.147.158:5001/upload/ |
| IOC Type : | url |
| Threat Type : | botnet_cc |
| Malware: | xmrig |
| Confidence Level : | Confidence level is moderate (50%) |
| Is compromised? : | False |
| ASN: | AS210644 AEZA-AS |
| Country: | RU |
| First seen: | 2023-07-08 06:45:37 UTC |
| Last seen: | 2023-08-27 20:12:23 UTC |
| UUID: | 6f8e80a3-1d1f-11ee-b1e6-42010aa4000a |
| Reporter | |
| Reward | 5 credits from ThreatFox |
| Tags: | POST |
| Reference: | https://tria.ge/230707-zfx1zacf4s/behavioral1 |
iam_py_test
XMRig sample seen sending data in a ZIP file to this URL via HTTP POST requests. The ZIP file included:- IP address and IP-based geolocation
- System information (such as installed security software)
- Passwords stolen from browsers
- A list of running processes
- A list of installed software
Sandbox reports:
- https://tria.ge/230707-zfx1zacf4s/behavioral1
- https://app.any.run/tasks/a08c3ee2-1506-4f9f-913b-902bbfd2f5ca
RU