ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 167.160.161.140:1012.

Database Entry


IOC ID:1556792
IOC: 167.160.161.140:1012
IOC Type :ip:port
Threat Type :botnet_cc
Malware: XWorm
Confidence Level : Confidence level is high (100%)
ASN:AS214943 RAILNET
Country:- US
First seen:2025-07-15 04:00:22 UTC
Last seen:never
UUID:3b3402af-6130-11f0-98eb-42010aa4000a
Reporter abuse_ch
Reward 50 credits from anonymous
10 credits from 01Xyris
50 credits from anonymous
10 credits from netresec
Tags:XWorm

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2025-07-15 04:00:25 3cdbdeddbb04d4382fdd85e848bbfbbcc01e3dfa25df1a96c7bc6a9d1f5bbd7f