ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 104.238.60.108:54372.

Database Entry


IOC ID:1738916
IOC: 104.238.60.108:54372
IOC Type :ip:port
Threat Type :botnet_cc
Malware: RansomHub
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
ASN:AS199959 CrownCloud
Country:- US
First seen:2026-01-30 02:43:40 UTC
Last seen:2026-03-31 07:44:01 UTC
UUID:7c7bb883-fd85-11f0-b7d0-42010aa4000a
Reporter abuse_ch
Reward 10 credits from scusi
Tags:drb-ra RansomHub

Avatar
abuse_ch
Possible win.ransomhub botnet C2 server