ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 83.222.190.174:443.

Database Entry


IOC ID:1519795
IOC: 83.222.190.174:443
IOC Type :ip:port
Threat Type :botnet_cc
Malware: NetSupportManager RAT
Malware alias:NetSupport
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS204428 SS-Net
Country:- BG
First seen:2025-05-12 05:00:31 UTC
Last seen:2025-07-08 18:04:28 UTC
UUID:fceaf175-2ed6-11f0-90ee-42010aa4000a
Reporter deccy
Reward 5 credits from ThreatFox
Tags:c2 ips malware net support RAT remote access

Avatar
deccy
IOCs gathered from reverse engineering sample obtained from live campaign. IP addresses resolved from domains which were listed in dropped file "client32.ini", which appears to be a config file for Net Support Manager.

185.39.17[.]38 appears to be located within the Russian Federation.
83.222.190[.]174 appears to be located in Bulgaria

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2025-05-30 15:15:17 e6d4e6a686547d40a4e00d827bb2d572f7a1f997785af50d6ecd1c1446e7afcf