ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 34.41.139.193:5202.

Database Entry


IOC ID:1748199
IOC: 34.41.139.193:5202
IOC Type :ip:port
Threat Type :botnet_cc
Malware: NetWire RC
Malware alias:NetWeird, NetWire, Recam
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS396982 GOOGLE-CLOUD-PLATFORM
Country:- US
First seen:2026-02-14 15:23:20 UTC
Last seen:2026-02-14 13:18:00 UTC
UUID:7f66db8d-098e-11f1-a068-42010aa4000a
Reporter Neiki
Reward 5 credits from ThreatFox
Tags:AutoIT botnet discovery DYNDNS execution infostealer NetWire persistence
Reference: https://www.threat.rip/file/42c6506adc777a13ce35b2bb1c0eb0476cc5055858a9fd0309a934cb2b9dece8/config