🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 101.43.156.141:6000.

Database Entry


IOC ID:1649892
IOC: 101.43.156.141:6000
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Ghost RAT
Malware alias:Farfli, Gh0st RAT, PCRat
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS45090 TENCENT-NET-AP
Country:- CN
First seen:2025-11-25 02:55:09 UTC
Last seen:never
UUID:279ab8d9-c9aa-11f0-a341-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:Gh0stRAT RAT

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2025-11-25 07:05:09 a95a25d7fe1d46df94f992e3a56be45edf5ef8f013aea95585a3b2f2d3bf9993
2025-11-25 02:55:11 3e48c8b65e16ddc17062ee3df281a35647bb5dcc9d4cbe24efd68046c96a55b3