ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 8.217.144.219:5677.

Database Entry


IOC ID:1821978
IOC: 8.217.144.219:5677
IOC Type :ip:port
Threat Type :botnet_cc
Malware: ValleyRAT
Malware alias:Winos
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
ASN:AS45102 ALIBABA-CN-NET
Country:- CN
First seen:2026-06-03 16:10:45 UTC
Last seen:never
UUID:c73ba769-5f66-11f1-a345-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:valleyrat_s2
Reference: https://bazaar.abuse.ch/sample/e306f2ec7aa41e7c60802c8156990b3d9c6949451ae72409646e4a7c15b6ebff/

Avatar
abuse_ch
valleyrat_s2 (aka Winos) botnet C2

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2026-07-02 22:15:11 eeb2d44d0f86670ac2ee5e0b7aa44ec41b7be9962359f59ac21f736d7b0e7889