ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 64.227.172.9:49152.

Database Entry


IOC ID:1873891
IOC: 64.227.172.9:49152
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Unknown Stealer
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS14061 DIGITALOCEAN-ASN
Country:- US
First seen:2026-08-14 06:20:12 UTC
Last seen:never
UUID:5feaadcc-9766-11f1-8a3d-42010aa4000a
Reporter meff
Reward 5 credits from ThreatFox
Tags:golang zimbra zimbra-exfil ZMBX
Reference: https://otx.alienvault.com/pulse/6a7e3df9ee68883c34577fe1

Avatar
meff
Targeted Linux/Go Zimbra mailbox exfiltration implant 'zimbra-exfil' (custom 'ZMBX' AES-256-GCM C2 with STATIC keys). Steals /opt/zimbra/store/*.msg. Self-deletes on start; lock /tmp/.cache.db. Confirmed by isolated detonation + end-to-end session decryption.