ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 185.19.85.175:48562.

Database Entry


IOC ID:159806
IOC: 185.19.85.175:48562
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Nanocore RAT
Malware alias:Nancrat, NanoCore
Confidence Level : Confidence level is elevated (75%)
ASN:AS48971 DATAWIRE-AS
Country:- CH
First seen:2021-07-12 13:22:58 UTC
Last seen:2023-09-27 18:39:11 UTC
UUID:46795557-e314-11eb-b17b-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:NanoCore
Reference: https://bazaar.abuse.ch/sample/b9b61268d1a21a119391e6316826c44425aec53a42155a7253f62639876eb687/

Avatar
abuse_ch
nanocore (aka Nancrat,NanoCore) botnet C2

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2021-11-15 09:22:11 d12e2d3f6bcf23db1062608289f9ebaec0ed535926d21340c2f6f89f2483ca38
2021-07-22 03:16:01 1bf63394fcf232d3a303d17df87252e2f47c43205edadc99ed15a50c9e193ebc