ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 89.184.185.198:443.

Database Entry


IOC ID:1836187
IOC: 89.184.185.198:443
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Cobalt Strike
Malware alias:Agentemis, BEACON, CobaltStrike, cobeacon
Confidence Level : Confidence level is high (92%)
Is compromised? : False
ASN:AS39647 REDHOSTING-AS
Country:- NL
First seen:2026-06-23 06:51:42 UTC
Last seen:never
UUID:6c8cca4d-6e8e-11f1-9258-42010aa4000a
Reporter Erebu
Reward 10 credits from anonymous
Tags:c2 erebus-v14 manual-override nation-state-hunter t1059_003 t1573_002

Avatar
Erebu
[MANUAL OVERRIDE — analyst-asserted, not auto-validated by EREBUS] Confirmed C2 infrastructure via EREBUS APEX | PROOF:JARM:497592101f7cc00f|TLS_C2:cobalt_strike|VT:3|ASN:AS39647 | MITRE:T1573.002,T1059.003,T1071.001,T1055 | GEO:NL | SRC:feed_urlhaus | TOOL:EREBUS-V14-WRAITH