ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 121.40.55.28:80.

Database Entry


IOC ID:1358666
IOC: 121.40.55.28:80
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Cobalt Strike
Malware alias:Agentemis, BEACON, CobaltStrike, cobeacon
Confidence Level : Confidence level is high (100%)
ASN:AS37963 ALIBABA-CN-NET
Country:- CN
First seen:2024-12-20 00:00:34 UTC
Last seen:2025-01-17 06:59:40 UTC
UUID:6fa777d9-be65-11ef-91ae-42010aa4000a
Reporter DonPasci
Reward 10 credits from anonymous
10 credits from anonymous
Tags:ALIBABA-CN-NET AS37963 c2 censys CobaltStrike cs-watermark-391144938
Reference: https://search.censys.io/hosts/121.40.55.28

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2024-12-24 18:20:20 18176a8ccc62cced9771a9fb2e2996016d79b2fbd700a15dbdd7467d1b998ee0