ThreatFox IOC Database
You are viewing the ThreatFox database entry for domain horecabot-dev.horecabid.com.
Database Entry
| IOC ID: | 1783024 |
|---|---|
| IOC: | horecabot-dev.horecabid.com |
| IOC Type : | domain |
| Threat Type : | botnet_cc |
| Malware: | Unknown malware |
| Confidence Level : | Confidence level is elevated (75%) |
| Is compromised? : | False |
| ASN: | AS14061 DIGITALOCEAN-ASN |
| Country: | US |
| First seen: | 2026-04-09 05:17:55 UTC |
| Last seen: | never |
| UUID: | 7ef3505a-337d-11f1-9af6-42010aa4000a |
| Reporter | |
| Reward | 5 credits from ThreatFox |
| Tags: | c2-infrastructure Digitalocean fake-sshd named-bot |
isaac1
Subdomain resolves to confirmed malicious IP165.22.97.111 (DigitalOcean Singapore AS14061,
flagged MALICIOUS on GreyNoise). That IP uploaded
a binary named 'sshd' (SHA256: 94f2e4d8d4436874)
to Cowrie SSH honeypot 2026-04-07 — likely SSH
backdoor masquerading as legitimate SSH daemon.
Not observed mass scanning on GreyNoise suggesting
targeted activity. Sister infrastructure to
aisha-bot.horecabid.com (159.65.5.193) on same
ASN. Part of apparent multi-bot operation under
horecabid.com domain.
US