ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 147.185.221.31:2232.

Database Entry


IOC ID:1569129
IOC: 147.185.221.31:2232
IOC Type :ip:port
Threat Type :botnet_cc
Malware: NjRAT
Malware alias:Bladabindi, Lime-Worm
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS400519 PLAYIT-GG
Country:- US
First seen:2025-08-15 18:25:10 UTC
Last seen:2025-09-13 11:44:04 UTC
UUID:2d54bbf3-7a05-11f0-b2c6-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:njrat

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2025-08-16 14:00:14 7a77a20ba754541141b20e39f88bbbba4b57af757c6906db5f1d8bb62126f262
2025-08-16 10:55:07 b6a26ecbd77d7d9788854ec96e18ced87388ea4e3f9b508faa81b11cd2e2a33c
2025-08-15 18:25:14 a3ce46df9a17c112b1b9b777a77fdad0ca1a0b3eb48c7f01d0ec32e71514af1c