ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 49.228.131.165:2427.

Database Entry


IOC ID:1519573
IOC: 49.228.131.165:2427
IOC Type :ip:port
Threat Type :botnet_cc
Malware: NjRAT
Malware alias:Bladabindi, Lime-Worm
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS133481 AIS-Fibre-AS-AP
Country:- TH
First seen:2025-05-11 18:50:03 UTC
Last seen:2025-05-20 10:26:27 UTC
UUID:bfd10e80-2e98-11f0-90ee-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:njrat

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2025-08-20 02:20:23 9a26897e1061fb4e54e78b427a4b605aba58e30243c3c72fc4d3d32fe58a703a
2025-05-11 18:50:06 2dba986101ad125c0be30b92fcc4098ae78187d68f25a85677dac2592b978e4d