🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 151.80.76.67:1224.

Database Entry


IOC ID:1906038
IOC: 151.80.76.67:1224
IOC Type :ip:port
Threat Type :botnet_cc
Malware: BeaverTail
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS16276 OVH
Country:- FR
First seen:2026-09-09 10:14:37 UTC
Last seen:never
UUID:e714e2b3-ac2c-11f1-b569-42010aa4000a
Reporter luisalbinati
Reward 5 credits from ThreatFox
Tags:BeaverTail ContagiousInterview FamousChollima folderOpen vscode-tasks

Avatar
luisalbinati
C2 observed 2026-09-07 15:46-15:58 UTC+1. RAT beaconed hostname/IP/MAC every 5s and executed payloads returned by the server. Port 1224/tcp is a known signature port for this family. Host is an OVH failover IP (151.80.76.64/29, org RDP Quick). Infection vector: malicious repo with .vscode/tasks.json using runOn folderOpen. Manually vetted on the victim host.