ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 43.224.226.119:8081.

Database Entry


IOC ID:1886573
IOC: 43.224.226.119:8081
IOC Type :ip:port
Threat Type :botnet_cc
Malware: RaspberryPiBotnet
Confidence Level : Confidence level is high (100%)
Is compromised? : True
ASN:AS400619 AROSS-AS
Country:- US
First seen:2026-08-25 06:48:28 UTC
Last seen:never
UUID:35be6351-a025-11f1-a7c1-42010aa4000a
Reporter shadowbyte1
Reward 5 credits from ThreatFox
Tags:botnet c2 cryptomining diicot ElPatrono1337 Mexals Zephyr
Reference: https://threatfox.abuse.ch/browse/tag/ElPatrono1337/

Avatar
shadowbyte1
Observed live on a compromised VPS - self-mutating cron persistence (staging dir
rotates hourly,
/var/tmp/<8-hex>/), SSH backdoor key planted in authorized_keys
(comment "ElPatrono1337"), binary at /tmp/cache (sha256
7d55a90710b8e79283efd756e8d3423fc23e0dcf742d6027b1a2a1b9d02a9c16). 125+ concurrent
P2P mesh connections on :8081 across ~19hrs uptime, both inbound and outbound.
Initial access via SSH password brute-force against a weak-password account.