ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 118.182.166.128:22.

Database Entry


IOC ID:1822893
IOC: 118.182.166.128:22
IOC Type :ip:port
Threat Type :payload_delivery
Malware: XOR DDoS
Malware alias:XORDDOS
Confidence Level : Confidence level is high (80%)
Is compromised? : False
ASN:AS4134 CHINANET-BACKBONE
Country:- CN
First seen:2026-06-06 06:03:44 UTC
Last seen:never
UUID:3ea63af3-6104-11f1-a345-42010aa4000a
Reporter nullblue67
Reward 5 credits from ThreatFox
Tags:BillGates DDoS ssh-bruteforce XOR.DDoS
Reference: https://twitter.com/NullBlue67

Avatar
nullblue67
XOR.DDoS classic deployer pattern chmod+x .randomstring/sshd nohup 2026-06-05 NullBlue67