ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 192.162.199.186:80.

Database Entry


IOC ID:1838161
IOC: 192.162.199.186:80
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Stealc
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
ASN:AS214351 FEMOIT
Country:- GB
First seen:2026-06-27 06:24:20 UTC
Last seen:never
UUID:292ea0aa-717d-11f1-97fa-42010aa4000a
Reporter gh0styippe
Reward 5 credits from ThreatFox
Tags:Loader Stealc stealer
Reference: https://app.any.run/tasks/69de2958-b593-4d93-802b-6b2601a2f93b

Avatar
gh0styippe
Stealc V2 C2 endpoint. Suricata confirmed StealC_V2 payload requests. Drops Solaris botnet (0_1670640.exe) and kernel driver defense evasion tool (WinSysKdrv.exe → EmbeddedDriverService.sys). Spamhaus DROP listed.