ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 103.7.81.202:22.

Database Entry


IOC ID:1783008
IOC: 103.7.81.202:22
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Unknown malware
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS45117 INPL-IN-AP
Country:- IN
First seen:2026-04-09 05:18:13 UTC
Last seen:never
UUID:bbff2045-337a-11f1-9af6-42010aa4000a
Reporter isaac1
Reward 5 credits from ThreatFox
Tags:Dropper libssh Windows

Avatar
isaac1
Observed uploading malicious dropper bundle to
Cowrie SSH honeypot 2026-04-07 via libssh_0.9.5
client. Files uploaded: rdpcIip.exe, upnpsetup,
sqhost.exe, zsvc, updates1.7z, updates2.7z,
7z.exe, 7z.dll. Malicious files disguised as
Windows updates. Logged in root/Qwerty1.