ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 27.25.158.13:8088.

Database Entry


IOC ID:1541654
IOC: 27.25.158.13:8088
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Cobalt Strike
Malware alias:Agentemis, BEACON, CobaltStrike, cobeacon
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS148981 CHINANET-HUBEI-SHIYAN-IDC
Country:- CN
First seen:2025-06-06 16:00:52 UTC
Last seen:2025-07-25 05:52:00 UTC
UUID:6bf9dd8d-42ef-11f0-a7f6-42010aa4000a
Reporter DonPasci
Reward 10 credits from anonymous
Tags:AS148981 c2 censys CHINANET-HUBEI-SHIYAN-IDC CobaltStrike cs-watermark-100000
Reference: https://search.censys.io/hosts/27.25.158.13

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2025-06-16 00:20:18 01bd3969ec4e836d74a51bffcedae71efeb1246c97f5bee97e2db1b280fb7e6b