🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 176.65.144.127:3851.

Database Entry


IOC ID:1892721
IOC: 176.65.144.127:3851
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Unknown RAT
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS209413 DEDIK-CH
First seen:2026-09-02 05:50:06 UTC
Last seen:never
UUID:1975a52f-a661-11f1-b569-42010aa4000a
Reporter Justice_Hammer
Reward 5 credits from ThreatFox
Tags:ComponentTask33 etherhiding msi NodeJS-RAT
Reference: https://github.com/Justice-Hammer/threat-hunting-detections/blob/main/30-research/RES-0007%20-%20ComponentTask33%20MSI%20Loader%20with%20On-Chain%20C2%20Discovery.md

Avatar
Justice_Hammer
Purpose-built Node.js RAT, cleartext JSON over WebSocket. The agent does not hardcode its C2: it resolves the panel URL at runtime from a Polygon contract (EtherHiding) 0xf9099d0d747368cce8C10226CC9AF2bFD4DDbCF4, getPanelUrl() selector 0x4ab7874e. setPanelUrl emits event topic0 0xb441e97002ff45bf8194f5209fab03d6ea838f98f2e8bf3392956dfc76103f6e, which publishes each new C2 on-chain the moment it is written - so the next C2 is readable before it appears on the wire. Operator rotated 2026-08-31 (3847 -> 3851 -> 3854) but never changed hosting - every C2 domain resolves to 176.65.144.127 (AS209413), so block the IP, not the domain.