ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 154.221.17.44:2888.

Database Entry


IOC ID:1332624
IOC: 154.221.17.44:2888
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Cobalt Strike
Malware alias:Agentemis, BEACON, CobaltStrike, cobeacon
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS142403 YISUCLOUDLTD-HK
Country:- HK
First seen:2024-10-02 06:31:45 UTC
Last seen:2026-06-10 18:45:49 UTC
UUID:ff00afbe-8087-11ef-894b-42010aa4000a
Reporter abuse_ch
Reward 10 credits from anonymous
10 credits from anonymous
10 credits from anonymous
Tags:CobaltStrike cs-watermark-666666666

Avatar
abuse_ch
Rogue Cobalt Strike C2 at 154.221.17.44 on port 2888 TCP using watermark 666666666 detected on 2024-10-01 08:25:31 UTC