🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://77.105.147.158:5001/upload/.

Database Entry


IOC ID:1136661
IOC: http://77.105.147.158:5001/upload/
IOC Type :url
Threat Type :botnet_cc
Malware: xmrig
Confidence Level : Confidence level is moderate (50%)
Is compromised? : False
ASN:AS210644 AEZA-AS
Country:- RU
First seen:2023-07-08 06:45:37 UTC
Last seen:2023-08-27 20:12:23 UTC
UUID:6f8e80a3-1d1f-11ee-b1e6-42010aa4000a
Reporter iam_py_test
Reward 5 credits from ThreatFox
Tags:POST
Reference: https://tria.ge/230707-zfx1zacf4s/behavioral1

Avatar
iam_py_test
XMRig sample seen sending data in a ZIP file to this URL via HTTP POST requests. The ZIP file included:
- IP address and IP-based geolocation
- System information (such as installed security software)
- Passwords stolen from browsers
- A list of running processes
- A list of installed software

Sandbox reports:
- https://tria.ge/230707-zfx1zacf4s/behavioral1
- https://app.any.run/tasks/a08c3ee2-1506-4f9f-913b-902bbfd2f5ca