ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 185.89.255.244:80.

Database Entry


IOC ID:1830369
IOC: 185.89.255.244:80
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Meterpreter
Confidence Level : Confidence level is high (91%)
Is compromised? : False
ASN:AS39440 NETPLUSFR-AS
Country:- CH
First seen:2026-06-11 18:09:01 UTC
Last seen:never
UUID:61064f90-65be-11f1-9e0e-42010aa4000a
Reporter Erebu
Reward 5 credits from ThreatFox
Tags:c2 erebus-v13 nation-state-hunter t1071_001 t1573_002

Avatar
Erebu
Confirmed C2 infrastructure via EREBUS APEX | PROOF:JARM:f9d831c53182f569(cobalt_strike_malleable)|TLS_C2:metasploit|ASN:UNK|TIER:T2 | MITRE:T1071.001,T1573.002,T1055,T1059.001 | GEO:UNK | SRC:shodan_AS202975 | TOOL:EREBUS-V13-WRAITH