ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 8.217.130.185:5678.

Database Entry


IOC ID:1838500
IOC: 8.217.130.185:5678
IOC Type :ip:port
Threat Type :botnet_cc
Malware: ValleyRAT
Malware alias:Winos
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
ASN:AS45102 ALIBABA-CN-NET
Country:- CN
First seen:2026-06-27 04:10:42 UTC
Last seen:never
UUID:2a15df82-71de-11f1-97fa-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:valleyrat_s2
Reference: https://bazaar.abuse.ch/sample/59afd76ba4c60df30d59b1cd3db92f203040ed0d4e84279434bd702c919e9273/

Avatar
abuse_ch
valleyrat_s2 (aka Winos) botnet C2