ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 209.54.103.189:63712.

Database Entry


IOC ID:1749273
IOC: 209.54.103.189:63712
IOC Type :ip:port
Threat Type :botnet_cc
Malware: XWorm
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS36352 AS-COLOCROSSING
Country:- US
First seen:2026-02-16 12:27:22 UTC
Last seen:2026-02-17 16:51:05 UTC
UUID:0df6ecfb-0b1b-11f1-a068-42010aa4000a
Reporter Neiki
Reward 5 credits from ThreatFox
Tags:AUTO-REG execution persistence RAT trojan XWorm
Reference: https://www.threat.rip/file/5cf73d1e70ec8fd9a781cd746c0485595f4f47c5913a4c353c3bc9c4f2796752/config