ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 147.185.221.30:18491.

Database Entry


IOC ID:1559203
IOC: 147.185.221.30:18491
IOC Type :ip:port
Threat Type :botnet_cc
Malware: XWorm
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS400519 PLAYIT-GG
Country:- US
First seen:2025-07-22 05:20:26 UTC
Last seen:2025-08-15 12:12:44 UTC
UUID:9329a45a-66bb-11f0-851c-42010aa4000a
Reporter abuse_ch
Reward 50 credits from anonymous
10 credits from 01Xyris
50 credits from anonymous
10 credits from netresec
Tags:XWorm

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2025-08-11 05:10:21 984b56f95e5a7a8023104e7ff5d2a7864968975fd69f7167fa728d1877cef4ba
2025-08-10 23:00:21 2d44c881f998667c46273f4dda60b479750467ac786c6246e7cace310a6fc98e
2025-07-22 05:20:28 ee32b20bd592238fa6513fca90e0f316c0d3d6073a39c3bfef8ced75bf2b6ace