ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 203.91.74.11:6666.

Database Entry


IOC ID:1569776
IOC: 203.91.74.11:6666
IOC Type :ip:port
Threat Type :botnet_cc
Malware: ValleyRAT
Malware alias:Winos
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS400619 AROSS-AS
Country:- US
First seen:2025-08-16 06:04:27 UTC
Last seen:never
UUID:dde0f8e9-7a66-11f0-b2c6-42010aa4000a
Reporter DonPasci
Reward 5 credits from ThreatFox
Tags:AS400619 c2 RAT triage ValleyRAT
Reference: https://tria.ge/250816-c3c8rahr2w

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2025-08-19 04:10:47 51350976fe04117bc613bd2e118f9bc6ad2cddfb71f360dacebf3bfd8583f046
2025-08-19 00:40:23 3b3b2c417b75c2fd8886f81031537200c05cf01d29f28b4ae95117206a8d5071
2025-08-18 23:40:21 41fd73e1d67148bc64e18697f82af08a496908a6ae4553f6219ac758df8427f7