🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 39.100.66.238:80.

Database Entry


IOC ID:1794910
IOC: 39.100.66.238:80
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Cobalt Strike
Malware alias:Agentemis, BEACON, CobaltStrike, cobeacon
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
ASN:AS37963 ALIBABA-CN-NET
Country:- CN
First seen:2026-04-20 10:52:12 UTC
Last seen:2026-09-27 08:46:34 UTC
UUID:fcb87c42-3ca6-11f1-8759-42010aa4000a
Reporter abuse_ch
Reward 10 credits from anonymous
Tags:CobaltStrike drb-ra

Avatar
abuse_ch
Possible Cobalt Strike botnet C2 server

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2026-09-25 03:00:26 2db23dbabf20814d496c61778c178ecf7a0da76f199f5476f45b4bbd650a4dd4