ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain horecabot-dev.horecabid.com.

Database Entry


IOC ID:1783024
IOC: horecabot-dev.horecabid.com
IOC Type :domain
Threat Type :botnet_cc
Malware: Unknown malware
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
ASN:AS14061 DIGITALOCEAN-ASN
Country:- US
First seen:2026-04-09 05:17:55 UTC
Last seen:never
UUID:7ef3505a-337d-11f1-9af6-42010aa4000a
Reporter isaac1
Reward 5 credits from ThreatFox
Tags:c2-infrastructure Digitalocean fake-sshd named-bot

Avatar
isaac1
Subdomain resolves to confirmed malicious IP
165.22.97.111 (DigitalOcean Singapore AS14061,
flagged MALICIOUS on GreyNoise). That IP uploaded
a binary named 'sshd' (SHA256: 94f2e4d8d4436874)
to Cowrie SSH honeypot 2026-04-07 — likely SSH
backdoor masquerading as legitimate SSH daemon.
Not observed mass scanning on GreyNoise suggesting
targeted activity. Sister infrastructure to
aisha-bot.horecabid.com (159.65.5.193) on same
ASN. Part of apparent multi-bot operation under
horecabid.com domain.