🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 194.48.248.94:80.

Database Entry


IOC ID:1954488
IOC: 194.48.248.94:80
IOC Type :ip:port
Threat Type :botnet_cc
Malware: SmartLoader
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
ASN:AS200019 AlexHost
Country:- MD
First seen:2026-10-06 08:17:55 UTC
Last seen:never
UUID:e77ae180-c15d-11f1-bd81-42010aa4000a
Reporter shmulc
Reward 5 credits from ThreatFox
Tags:Github LuaJIT Polygon SmartLoader

Avatar
shmulc
C2 values set in the SmartLoader Polygon dead-drop contract 0x1823A9a0Ec8e0C25dD957D0841e3D41a4474bAdc (getData()): 194.48.248.94 on 2026-08-11, 185.10.68.110 on 2026-09-17 (current). Delivered through fake GitHub repos with LuaJIT kit ZIPs. Read from the chain only, never contacted.