ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 65.21.206.125:13957.

Database Entry


IOC ID:192172
IOC: 65.21.206.125:13957
IOC Type :ip:port
Threat Type :botnet_cc
Malware: RedLine Stealer
Malware alias:RECORDSTEALER
Confidence Level : Confidence level is high (100%)
ASN:AS24940 HETZNER-AS
Country:- DE
First seen:2021-08-18 20:26:00 UTC
Last seen:2023-08-01 18:04:18 UTC
UUID:806fe635-0062-11ec-830d-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:RedLineStealer

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2021-08-19 10:41:01 f6e8f13adceaaac1b6e35e41b0f2442bbd9e11288895b4fe9b40b0f97b83d7e2
2021-08-19 08:35:52 a02e5e7cdf6be1972e1e08c12ca126431046f638a5cbe00d5bbd8cdb1bf68480
2021-08-18 20:30:56 cd62e4fee322712a02787bcc881712ee41b99f8e8de3e425d90399bf5bf5fe75