ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 192.159.99.244:1023.

Database Entry


IOC ID:1564855
IOC: 192.159.99.244:1023
IOC Type :ip:port
Threat Type :botnet_cc
Malware: XWorm
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
ASN:AS210558 services-1337-gmbh
Country:- DE
First seen:2025-08-06 08:31:20 UTC
Last seen:2025-08-15 12:12:44 UTC
UUID:ba9487f7-729f-11f0-851c-42010aa4000a
Reporter abuse_ch
Reward 50 credits from anonymous
10 credits from 01Xyris
50 credits from anonymous
10 credits from netresec
Tags:XWorm
Reference: https://bazaar.abuse.ch/sample/d9a71562e105fe4d78286dd788465a07d7200aa4a66daae81d3f4630eef120b9/

Avatar
abuse_ch
xworm botnet C2

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2025-08-06 08:45:31 64a3b19eb4e95eb953413d60ceabf46b451920790778a19f166922b6c3f89e50
2025-08-06 08:40:31 3da7ec5adf7c0051c6d7b028f1c192bb005dc03b05db805cd217a75e8e40a6e8