ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://107.189.20.142/cafc9966dc4c4240.php.

Database Entry


IOC ID:1684862
IOC: http://107.189.20.142/cafc9966dc4c4240.php
IOC Type :url
Threat Type :botnet_cc
Malware: Stealc
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS14956 ROUTERHOSTING
Country:- IR
First seen:2025-12-22 21:35:17 UTC
Last seen:2025-12-28 15:56:34 UTC
UUID:1bc7732a-df7e-11f0-9957-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:Steal

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2025-12-22 21:35:20 cef044e0065c13da7b0d6c4b4d985dd4c24d86893d4f0084f1d844972cfd3927