🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 20.187.77.65:443.

Database Entry


IOC ID:1901348
IOC: 20.187.77.65:443
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Unknown RAT
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS8075 MICROSOFT-CORP-MSN-AS-BLOCK
Country:- US
First seen:2026-09-05 12:23:36 UTC
Last seen:never
UUID:02d0e1cc-a923-11f1-b569-42010aa4000a
Reporter KabirAcharya
Reward 5 credits from ThreatFox
Tags:azure c2 Hong-Kong origin ProRAM RAT
Reference: https://kabir.au/blog/speedybee-bootcss-sub-store-malware-chain

Avatar
KabirAcharya
Exposed origin of clash-verge-upgrade.com, the primary ProRAM WebSocket C2. Direct HTTP to the IP redirects to the C2 domain, and TLS on 443 presents its certificate. Microsoft service tags place the IP in Azure East Asia (Hong Kong).