🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 223.19.66.178:22.

Database Entry


IOC ID:1915665
IOC: 223.19.66.178:22
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Payload
Confidence Level : Confidence level is high (80%)
Is compromised? : True
ASN:AS9304 HUTCHISON-AS-AP
Country:- HK
First seen:2026-09-12 13:44:24 UTC
Last seen:never
UUID:7bacc97f-aead-11f1-b569-42010aa4000a
Reporter Chuan_jian_guo
Reward 5 credits from ThreatFox
Tags:mikrotik sms-abuse ssh-botnet telegram-tdata
Reference: https://tonystech.net/posts/mischarachterized-microtik-attack/

Avatar
Chuan_jian_guo
Documented multi-vector Linux botnet node (2018-2026 campaign): runs /ip cloud print RouterOS check, enumerates Telegram Desktop tdata (locate D877F783D5D3EF8Cs = session auth file) for account hijack, enumerates SMS modem/gateway paths (ttyGSM/ttyUSB-mod/qmuxd/smsd), rival miner check. Dictionary root/{root,admin,12345,guest,123456}. Captured 2026-09-05 on SSH honeypot.