ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain tcp.tcptunnel.shop.

Database Entry


IOC ID:1832172
IOC: tcp.tcptunnel.shop
IOC Type :domain
Threat Type :botnet_cc
Malware: Unknown RAT
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS48753 GOOGLE-CLOUD-PLATFORM
Country:- US
First seen:2026-06-15 07:03:54 UTC
Last seen:2026-06-14 21:00:57 UTC
UUID:23ecbd6b-6834-11f1-9e0e-42010aa4000a
Reporter Anonymous
Reward 5 credits from ThreatFox
Tags:FRP liberium LiberiumRAT port ports

Avatar
Anonymous
C2 address extracted from malware sample. Decoded dynamically via breakpoint on decryption function in dnSpy.