ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 178.16.54.109:6000.

Database Entry


IOC ID:1831590
IOC: 178.16.54.109:6000
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Phorpiex
Malware alias:Tldr, Trik, TwizT, phorphiex
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
ASN:AS202412 OMEGATECH-AS
Country:- GB
First seen:2026-06-13 15:05:03 UTC
Last seen:never
UUID:f056a682-667c-11f1-9e0e-42010aa4000a
Reporter gh0styippe
Reward 5 credits from ThreatFox
Tags:Loader phorpiex Worm
Reference: https://tria.ge/260612-tw2ffaa16r

Avatar
gh0styippe
Phorpiex C2/payload distribution. Contacted on port 80 and 6000 in both sandbox runs. Drops multiple secondary payloads (XMRig miner via service "winmgr", NeedleStealer browser credential theft).