ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 2.11.150.174:8081.

Database Entry


IOC ID:1190006
IOC: 2.11.150.174:8081
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Raspberry Robin
Malware alias:RaspberryRobin, QNAP-Worm, LINK_MSIEXEC
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
ASN:AS3215 AS3215
Country:- FR
First seen:2023-10-17 10:23:12 UTC
Last seen:never
UUID:c2e0e825-6cd4-11ee-a915-42010aa4000a
Reporter Curry_Beans
Reward 5 credits from ThreatFox
Tags:RaspberryRobin usb Worm

Avatar
Curry_Beans
82.124..243.57 is IP of compromised QNAP hosting 0t[.]yt domain.
Rotates with 3 or 4 other IPs.
Domain has been in use by RR since October '22 or earlier.