🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 85.137.53.167:3169.

Database Entry


IOC ID:1959712
IOC: 85.137.53.167:3169
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Mirai
Malware alias:Katana
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
ASN:AS43641 Sollutium-NL
Country:- PL
First seen:2026-10-10 06:01:50 UTC
Last seen:never
UUID:8de8bd56-c44b-11f1-bd13-42010aa4000a
Reporter ksi_digital
Reward 50 credits from anonymous
Tags:cowrie elf honeypot MIPS Mirai telnet
Reference: https://bazaar.abuse.ch/sample/9e3aa12ebf0d32b7e315de5e0fc742c6f504e35ddedf2ba4205b9bd56ad52224/

Avatar
ksi_digital
Mirai C2 (TCP 3169) of the bot served by 85.137.53.167. Observed by running http://85.137.53.167:5000/bins/client_mips (sha256 9e3aa12ebf0d32b7e315de5e0fc742c6f504e35ddedf2ba4205b9bd56ad52224, MIPS big-endian, on MalwareBazaar as Mirai since 2026-09-27; we took it from MalwareBazaar) offline in our sandbox under qemu-mips as root: it connects to 85.137.53.167:3169 and keeps retrying (21 SYNs in 180 s at the sandbox router), no other destination. The same host is in current use as a loader host: on 2026-10-09 17:27 UTC and 2026-10-10 00:20 UTC 172.166.156.160 logged in to our Cowrie telnet honeypot and ran './wget.sh telnet' fetched from http://85.137.53.167:24380/bins/telnet/wget.sh (that server returned 404 to us). Not contacted, liveness of :3169 not verified. Not on ThreatFox at submission. Confidence 75 = observed dynamically in an offline sandbox, not contacted.