ThreatFox IOC Database
You are viewing the ThreatFox database entry for ip:port 45.147.97.142:8081.
Database Entry
| IOC ID: | 1886584 |
|---|---|
| IOC: | 45.147.97.142:8081 |
| IOC Type : | ip:port |
| Threat Type : | botnet_cc |
| Malware: | RaspberryPiBotnet |
| Confidence Level : | Confidence level is high (100%) |
| Is compromised? : | True |
| ASN: | AS62000 AS62000 |
| Country: | FR |
| First seen: | 2026-08-25 06:48:22 UTC |
| Last seen: | never |
| UUID: | 368194b1-a025-11f1-a7c1-42010aa4000a |
| Reporter | |
| Reward | 5 credits from ThreatFox |
| Tags: | botnet c2 cryptomining diicot ElPatrono1337 Mexals Zephyr |
| Reference: | https://threatfox.abuse.ch/browse/tag/ElPatrono1337/ |
shadowbyte1
Observed live on a compromised VPS - self-mutating cron persistence (staging dirrotates hourly,
/var/tmp/<8-hex>/), SSH backdoor key planted in authorized_keys
(comment "ElPatrono1337"), binary at /tmp/cache (sha256
7d55a90710b8e79283efd756e8d3423fc23e0dcf742d6027b1a2a1b9d02a9c16). 125+ concurrent
P2P mesh connections on :8081 across ~19hrs uptime, both inbound and outbound.
Initial access via SSH password brute-force against a weak-password account.
FR