ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 20.2.211.167:80.

Database Entry


IOC ID:1766799
IOC: 20.2.211.167:80
IOC Type :ip:port
Threat Type :botnet_cc
Malware: ValleyRAT
Malware alias:Winos
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS8075 MICROSOFT-CORP-MSN-AS-BLOCK
Country:- US
First seen:2026-03-15 06:30:13 UTC
Last seen:never
UUID:6c53ca93-2038-11f1-9af6-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:RAT ValleyRAT

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2026-03-15 06:30:16 a5c01d96c6269cf716cfe3bfeba1f9a5b6eb401892aaf14de5b587d034a518cd