🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 45.95.168.149:888.

Database Entry


IOC ID:1887601
IOC: 45.95.168.149:888
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Unknown malware
Confidence Level : Confidence level is high (90%)
Is compromised? : False
ASN:AS211619 MAXKO
Country:- HR
First seen:2026-08-26 05:46:33 UTC
Last seen:never
UUID:7b110059-a0ba-11f1-a7c1-42010aa4000a
Reporter eFeSpain
Reward 5 credits from ThreatFox
Tags:booter DDoS gaming IoT KHserver SBIDIOT
Reference: https://blog.efespain.com/posts/capitulo-12-khserver-ghidra/

Avatar
eFeSpain
C2 of an IoT DDoS-for-hire botnet (booter) captured in my own SSH honeypot on 2026-08-25. Address is not stored as a string: it is assembled at runtime from four octet tables in initConnection, port 888, 30s timeout — recovered with Ghidra. Attack commands include FORTNITE, COD, R6, RUST, VSE, OVHHEX and NFOHEX (game-server hosts). Carries 15 CVE-labelled functions that are probes, not exploits: they fingerprint vulnerable hosts and report them back with REPORT EXPLOIT %s %s:%d. Descendant of SBIDIOT (2021): shares command vocabulary and the exact UDPBYPASS payload string. Internal marks: KHserverHACKER, KHcommSOCK. Loader: handshakebins.sh from 213.232.114.14. Full static analysis in the reference.