ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 196.251.84.252:1003.

Database Entry


IOC ID:1582380
IOC: 196.251.84.252:1003
IOC Type :ip:port
Threat Type :botnet_cc
Malware: XWorm
Confidence Level : Confidence level is high (100%)
ASN:AS401120 CHEAPY-HOST
Country:- US
First seen:2025-09-05 22:00:34 UTC
Last seen:never
UUID:bf5633c2-8aa3-11f0-bfa6-42010aa4000a
Reporter abuse_ch
Reward 10 credits from 01Xyris
50 credits from anonymous
10 credits from netresec
10 credits from akanine1337
10 credits from Saber
Tags:XWorm

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2025-09-06 12:16:08 cc517fde471895786ec1ed2d1c5b192849565d7c6725bcc19579613b8ad2d564
2025-09-05 22:00:36 8fa6a5b34fac89062c13172061b58a0afeb4c034edf3a2de0f8c3a37ba444419