🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 49.232.159.76:8000.

Database Entry


IOC ID:1552102
IOC: 49.232.159.76:8000
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Ghost RAT
Malware alias:Farfli, Gh0st RAT, PCRat
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS45090 TENCENT-NET-AP
Country:- CN
First seen:2025-07-01 16:01:24 UTC
Last seen:2025-07-02 04:00:24 UTC
UUID:a32c488e-5694-11f0-a7f6-42010aa4000a
Reporter DonPasci
Reward 5 credits from ThreatFox
Tags:AS45090 c2 censys Gh0st RAT TENCENT-NET-AP
Reference: https://search.censys.io/hosts/49.232.159.76

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2025-07-04 09:15:18 e1b5ae8f8dbc1c90f63cb4bd97e365d5813e6601fee3a5df97b2e9807ba3781b