ThreatFox IOC Database
You are viewing the ThreatFox database entry for url http://172.86.91.94/api/.
Database Entry
| IOC ID: | 1801451 |
|---|---|
| IOC: | http://172.86.91.94/api/ |
| IOC Type : | url |
| Threat Type : | botnet_cc |
| Malware: | Anatsa |
| Malware alias: | ReBot, TeaBot, Toddler |
| Confidence Level : | Confidence level is moderate (49%) |
| Is compromised? : | False |
| ASN: | AS14956 ROUTERHOSTING |
| Country: | US |
| First seen: | 2026-04-28 07:20:47 UTC |
| Last seen: | 2026-04-28 12:21:23 UTC |
| UUID: | ce28b391-42d1-11f1-8759-42010aa4000a |
| Reporter | |
| Reward | 5 credits from ThreatFox |
| Reference: | https://www.cyberaccord.com/fake-document-reader-on-google-play-with-10k-downloads-installing-anatsa-malware/ |
US