ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 193.149.187.77:80.

Database Entry


IOC ID:1854530
IOC: 193.149.187.77:80
IOC Type :ip:port
Threat Type :payload_delivery
Malware: Unknown malware
Confidence Level : Confidence level is elevated (75%)
Is compromised? : True
ASN:AS399629 BLNWX
Country:- NL
First seen:2026-07-21 05:20:01 UTC
Last seen:never
UUID:bb12ea7c-847c-11f1-8973-42010aa4000a
Reporter DENNISAROSS
Reward 5 credits from ThreatFox
Tags:BL-Networks BlankGrabber PyInstaller python stealer

Avatar
DENNISAROSS
Open directory on BL Networks (AS399629) serving BlankGrabber PyInstaller Python 3.7 runtime components (python37.zip, sqlite3.dll, libssl-1_1-x64.dll, libcrypto-1_1-x64.dll, _ctypes.pyd). Directory consistent with staged payload delivery. Files timestamped 2026-01-31, server active since at least 2026-06-02 per Validin crawl history. urlscan ML score 97/100 malicious. stub.pyw (SHA256: 54415e8a8d8e1ad25fdb246d9dfd50c76dce805a47b92d84539f23d14f6ee31b) confirmed BlankGrabber entry point.