🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 134.122.200.153:8151.

Database Entry


IOC ID:1931083
IOC: 134.122.200.153:8151
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Unknown malware
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS152194 CTGSERVERLIMITED-AS-AP
Country:- HK
First seen:2026-09-24 04:58:49 UTC
Last seen:never
UUID:e547f643-b79b-11f1-abee-42010aa4000a
Reporter devmihaylov
Reward 5 credits from ThreatFox
Tags:c2 Endpoint-Central ManageEngine RMM-abuse
Reference: https://x.com/devmihaylov/status/2102883134996189479

Avatar
devmihaylov
Attacker-run ManageEngine Endpoint Central server that the installed agent enrolls into, read out of the loader's bundled DCAgentServerInfo.json (auth key 7207f7d8ca41da69f1d39f42cb85b60a), it gives the operator software deployment and remote command execution over any host that ran the loader.