ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 193.107.109.59:443.

Database Entry


IOC ID:1295407
IOC: 193.107.109.59:443
IOC Type :ip:port
Threat Type :botnet_cc
Malware: FAKEUPDATES
Malware alias:FakeUpdate, GhoLoader, SocGholish
Confidence Level : Confidence level is moderate (50%)
ASN:AS214379 SPN
Country:- UA
First seen:2024-07-07 03:48:48 UTC
Last seen:never
UUID:d1771c6c-3c13-11ef-8261-42010aa4000a
Reporter drb_ra
Reward 5 credits from ThreatFox
Tags:MDCLOUD SocGholish
Reference: https://search.censys.io/hosts/193.107.109.59

Avatar
drb_ra
SocGholish Found
C2: 193[.]107[.]109[.]59:443
Certificate: 6696699d48806196fa6342b16ba59d569297d18e4db2072c33dc0f8dd3d2a10b
Country: Germany
ASN: MDCLOUD