🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 143.92.38.221:8151.

Database Entry


IOC ID:1931090
IOC: 143.92.38.221:8151
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Unknown malware
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS152194 CTGSERVERLIMITED-AS-AP
Country:- HK
First seen:2026-09-24 04:58:44 UTC
Last seen:never
UUID:8917d970-b79d-11f1-abee-42010aa4000a
Reporter devmihaylov
Reward 5 credits from ThreatFox
Tags:c2 Endpoint-Central ManageEngine RMM-abuse
Reference: https://x.com/devmihaylov/status/2102883134996189479

Avatar
devmihaylov
Attacker-run ManageEngine Endpoint Central enrollment servers from two sibling kits on gfgxcx.com, both port 8151 with the same auth key 7207f7d8ca41da69f1d39f42cb85b60a and the same root CAs as 134.122.200.153. One operator, three servers, the ZIP filename encodes each server's last octet.