ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 172.94.127.2:4000.

Database Entry


IOC ID:1557189
IOC: 172.94.127.2:4000
IOC Type :ip:port
Threat Type :botnet_cc
Malware: XWorm
Confidence Level : Confidence level is high (100%)
ASN:AS7040 NETMINDERS
Country:- CA
First seen:2025-07-16 05:00:20 UTC
Last seen:never
UUID:c61d6012-6201-11f0-98eb-42010aa4000a
Reporter abuse_ch
Reward 50 credits from anonymous
10 credits from 01Xyris
50 credits from anonymous
10 credits from netresec
Tags:XWorm

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2025-07-16 05:00:22 ddaa7b8bf32ddd938fccc8358fda317278cf91cfe387368ec5e254e2191e56c8