ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 45.61.136.49:80.

Database Entry


IOC ID:1854563
IOC: 45.61.136.49:80
IOC Type :ip:port
Threat Type :payload_delivery
Malware: Unknown malware
Confidence Level : Confidence level is high (80%)
Is compromised? : True
ASN:AS399629 BLNWX
Country:- NL
First seen:2026-07-21 05:20:12 UTC
Last seen:never
UUID:9f3678f8-848f-11f1-8973-42010aa4000a
Reporter DENNISAROSS
Reward 5 credits from ThreatFox
Tags:Amos AtomicStealer BL-Networks Mach-O macOS payload-delivery

Avatar
DENNISAROSS
Confirmed AMOS (Atomic macOS Stealer) staging server on BL Networks (AS399629). Microsoft Defender detection: Trojan:MacOS/AmosStealer.DB!MTB. VT: 7 malicious (alphaMountain: Phishing, Webroot: Phishing and Other Frauds). Apache/2.4.52 (Ubuntu 22.04). Active open directory since 2026-06-02 per Validin crawl history, stable content since 2026-06-07. Identical Apache header fingerprint (f46066c8e5604431afdc) to confirmed AMOS node at 64.52.80.235, BlankGrabber node at 193.149.187.77, and Banana RAT C2 at 162.33.178.68 — all on AS399629. Second confirmed AMOS staging node in this BL Networks cluster.