🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 108.181.175.198:7000.

Database Entry


IOC ID:1881337
IOC: 108.181.175.198:7000
IOC Type :ip:port
Threat Type :botnet_cc
Malware: XWorm
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS40676 AS40676
Country:- US
First seen:2026-08-19 06:04:50 UTC
Last seen:never
UUID:1961c683-9b37-11f1-a7c1-42010aa4000a
Reporter isahjs6
Reward 10 credits from Saber
10 credits from anonymous
Tags:HTA mexico WhatsApp XWorm
Reference: https://bazaar.abuse.ch/sample/3dd9f794833b29db94173ee707a300162e388cf75357e494e328954b5d61c650/

Avatar
isahjs6
XWorm C2, same operator/host as AsyncRAT. Hollowed into RegAsm.exe. Mutex <123456789>, group AGOSTO2, USB spreading enabled.