ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 51.255.28.210:8081.

Database Entry


IOC ID:1886560
IOC: 51.255.28.210:8081
IOC Type :ip:port
Threat Type :botnet_cc
Malware: RaspberryPiBotnet
Confidence Level : Confidence level is high (100%)
Is compromised? : True
ASN:AS16276 OVH
Country:- FR
First seen:2026-08-25 06:48:37 UTC
Last seen:never
UUID:34a5591e-a025-11f1-a7c1-42010aa4000a
Reporter shadowbyte1
Reward 5 credits from ThreatFox
Tags:botnet c2 cryptomining diicot ElPatrono1337 Mexals Zephyr
Reference: https://threatfox.abuse.ch/browse/tag/ElPatrono1337/

Avatar
shadowbyte1
Observed live on a compromised VPS - self-mutating cron persistence (staging dir
rotates hourly,
/var/tmp/<8-hex>/), SSH backdoor key planted in authorized_keys
(comment "ElPatrono1337"), binary at /tmp/cache (sha256
7d55a90710b8e79283efd756e8d3423fc23e0dcf742d6027b1a2a1b9d02a9c16). 125+ concurrent
P2P mesh connections on :8081 across ~19hrs uptime, both inbound and outbound.
Initial access via SSH password brute-force against a weak-password account.