ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 172.245.244.78:4184.

Database Entry


IOC ID:1493221
IOC: 172.245.244.78:4184
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Nanocore RAT
Malware alias:Nancrat, NanoCore
Confidence Level : Confidence level is elevated (75%)
ASN:AS36352 AS-COLOCROSSING
Country:- US
First seen:2025-04-17 13:06:54 UTC
Last seen:2025-05-13 09:04:07 UTC
UUID:d5db9a89-1b8c-11f0-adfc-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:NanoCore
Reference: https://bazaar.abuse.ch/sample/198596f7bb8893e68b762503c8da049f8b263b3c7e5b3210bd7eb1d5c89d7c10/

Avatar
abuse_ch
nanocore (aka Nancrat,NanoCore) botnet C2

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2025-05-01 07:07:27 fef63e35d792b15a6c741896dc2998e9d359ea97f3ded6b4dd48f74ef48ebc92
2025-05-01 07:07:15 198596f7bb8893e68b762503c8da049f8b263b3c7e5b3210bd7eb1d5c89d7c10