ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 165.22.97.111:22.

Database Entry


IOC ID:1783013
IOC: 165.22.97.111:22
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Unknown malware
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS14061 DIGITALOCEAN-ASN
Country:- US
First seen:2026-04-09 05:18:10 UTC
Last seen:never
UUID:b7ad85f7-337b-11f1-9af6-42010aa4000a
Reporter isaac1
Reward 5 credits from ThreatFox
Tags:backdoor Digitalocean fake-sshd named-bot ssh

Avatar
isaac1
Confirmed malicious DigitalOcean VPS
(AS14061, Singapore). Active today
2026-04-08. Not spoofable — confirmed
real source. RDNS horecabot.horecabid.com
indicates deliberately configured named
bot infrastructure rather than compromised
machine. Uploaded binary named 'sshd' to
Cowrie SSH honeypot 2026-04-07 — likely
SSH backdoor masquerading as legitimate
SSH daemon (SHA256: 94f2e4d8d4436874...).
Same fake sshd hash observed from
158.51.96.38 on 2026-04-06 suggesting
coordinated campaign. Logged in via
root/ubuntu. SSH-2.0-Go client indicating
automated tooling.