ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain romanovas.duckdns.org.

Database Entry


IOC ID:1545803
IOC: romanovas.duckdns.org
IOC Type :domain
Threat Type :botnet_cc
Malware: NjRAT
Malware alias:Bladabindi, Lime-Worm
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS42708 GLESYS
Country:- SE
First seen:2025-06-17 07:09:59 UTC
Last seen:2025-06-28 22:26:12 UTC
UUID:147140b8-4b4a-11f0-a7f6-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:njrat RAT
Reference: https://bazaar.abuse.ch/sample/a1e7b215e1864b59a808e8b63356eca78629563744d6deced84afd55690877c1/

Avatar
abuse_ch
Port 5552 TCP