ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://64.227.172.9:8033/client_linux.

Database Entry


IOC ID:1873892
IOC: http://64.227.172.9:8033/client_linux
IOC Type :url
Threat Type :payload_delivery
Malware: Unknown Stealer
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS14061 DIGITALOCEAN-ASN
Country:- US
First seen:2026-08-14 06:20:11 UTC
Last seen:never
UUID:603047d2-9766-11f1-8a3d-42010aa4000a
Reporter meff
Reward 5 credits from ThreatFox
Tags:golang zimbra zimbra-exfil ZMBX
Reference: https://otx.alienvault.com/pulse/6a7e3df9ee68883c34577fe1

Avatar
meff
Targeted Linux/Go Zimbra mailbox exfiltration implant 'zimbra-exfil' (custom 'ZMBX' AES-256-GCM C2 with STATIC keys). Steals /opt/zimbra/store/*.msg. Self-deletes on start; lock /tmp/.cache.db. Confirmed by isolated detonation + end-to-end session decryption.