ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 87.120.187.72:8433.

Database Entry


IOC ID:1886326
IOC: 87.120.187.72:8433
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Unidentified APK 001
Confidence Level : Confidence level is moderate (50%)
Is compromised? : False
ASN:AS215439 PLAY2GO-NET
Country:- RU
First seen:2026-08-25 06:49:06 UTC
Last seen:never
UUID:ec5741a1-9fd1-11f1-a7c1-42010aa4000a
Reporter mikhailyuminov
Reward 5 credits from ThreatFox
Tags:Android banker c2 infostealer Mamont SMS-stealer spyagent
Reference: https://www.virustotal.com/gui/file/713165d12b900b518e26cbab760b69e8234e312703e4a88f9a37b0ccc2b66dee

Avatar
mikhailyuminov
Command-and-control server for an Android banking trojan (Mamont / SpyAgent family). Infected devices register to /api/v1/register and open a WebSocket to /ws on port 8433 for remote tasking. Malware intercepts SMS (including banking OTPs), steals contacts, and is remotely controlled via C2 + FCM push. Confirmed via VirusTotal sandbox analysis. Distributed through Telegram disguised as leaked video / "SMS bomber" tools. Two distinct samples observed beaconing to the same host.