🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 78.46.89.102:7777.

Database Entry


IOC ID:1888825
IOC: 78.46.89.102:7777
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Unknown malware
Confidence Level : Confidence level is high (90%)
Is compromised? : False
ASN:AS24940 HETZNER-AS
Country:- DE
First seen:2026-08-27 07:21:39 UTC
Last seen:never
UUID:cbfaed81-a19d-11f1-9e13-42010aa4000a
Reporter eFeSpain
Reward 5 credits from ThreatFox
Tags:ADB Android cryptomining IoT monero Trinity xmrig
Reference: https://blog.efespain.com/posts/capitulo-13-trinity-propagador/

Avatar
eFeSpain
Private Monero mining pools used by the Trinity/ADB.Miner kit, captured in my own ADB honeypot (port 5555) on 2026-08-26. The kit arrives as three files pushed over ADB; the 'endat' blob is not encrypted but a self-extracting container holding ufo.apk (the 2018 Coinhive APK, unchanged), rtsh.sh (replaces /system/bin/debuggerd for persistence) and a 657,948-byte static ARM build of XMRig. Both pool addresses are hardcoded in that XMRig build alongside the operator wallet 44XT4KvmobTQfeWa6PCQF5RDosr2MLWm43AsaE3o5iNRXXTfDbYk2VPHTVedTQHZyfXNzMn8YYF2466d3FSDT7gJS8gdHAr. 139.99.9.133:5555 is the one actually dialled at startup (confirmed by running the miner inside an isolated network namespace with a blackhole interface and reading /proc/net/tcp; no packet ever left the lab); 78.46.89.102:7777 is the fallback. The wallet does not appear on SupportXMR, MoneroOcean, Nanopool or HashVault - these are the operator's own pools. NOTE: a second Monero address inside the binary (48edfHu7V9Z84Yzz...) is XMRig's stock donation wallet and must NOT be attributed to the actor. Full static+dynamic analysis in the reference.