ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 159.65.5.193:22.

Database Entry


IOC ID:1783025
IOC: 159.65.5.193:22
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Unknown malware
Confidence Level : Confidence level is moderate (50%)
Is compromised? : False
ASN:AS14061 DIGITALOCEAN-ASN
Country:- US
First seen:2026-04-09 05:17:53 UTC
Last seen:never
UUID:c3cb3113-337d-11f1-9af6-42010aa4000a
Reporter isaac1
Reward 5 credits from ThreatFox
Tags:c2-infrastructure Digitalocean named-bot targeted

Avatar
isaac1
IP resolves to aisha-bot.horecabid.com. Sister
infrastructure to 165.22.97.111 (horecabot-dev.
horecabid.com) which uploaded fake sshd backdoor
to Cowrie SSH honeypot 2026-04-07. Both IPs on
DigitalOcean Singapore AS14061. Neither observed
on GreyNoise suggesting deliberate targeted
activity. Linked by shared domain infrastructure
only, not directly observed attacking honeypot.