ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://37.0.8.80/index.php.

Database Entry


IOC ID:162929
IOC: http://37.0.8.80/index.php
IOC Type :url
Threat Type :botnet_cc
Malware: Azorult
Malware alias:PuffStealer, Rultazo
Confidence Level : Confidence level is elevated (75%)
ASN:AS48628 CoreISP
Country:- GB
First seen:2021-07-26 13:08:05 UTC
Last seen:2023-09-27 14:03:18 UTC
UUID:841bead2-ee12-11eb-b17b-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:AZORult
Reference: https://bazaar.abuse.ch/sample/462f4e639cead04d64436b603d4e0a62816fcaa0b03c6390d6f2c6ff366da6c7/

Avatar
abuse_ch
azorult (aka PuffStealer,Rultazo) botnet C2

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2021-07-27 08:50:27 120fcd098c502894515feb3814bd6edc34ceb13648dcfae2a22c4f4e2166ace2
2021-07-26 14:25:43 aae9e232abe6255663d52d2db42079a395e3e50f712b8a39f269116ed419f8c6