🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 206.189.164.5:44559.

Database Entry


IOC ID:1959724
IOC: 206.189.164.5:44559
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Mirai
Malware alias:Katana
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS14061 DIGITALOCEAN-ASN
Country:- US
First seen:2026-10-10 06:01:47 UTC
Last seen:never
UUID:db116b6f-c451-11f1-bd13-42010aa4000a
Reporter ksi_digital
Reward 50 credits from anonymous
Tags:cowrie dns-xor elf honeypot Mirai telnet x86
Reference: https://threatfox.abuse.ch/ioc/1959715/

Avatar
ksi_digital
Second Mirai C2 of the 176.65.139.40 kit, confirmed live; sibling of ThreatFox 1959715 (159.65.67.52:44992). The kit's x86 bot (sha256 55d19b5c675819d5d2492e10bd44028d3e02426c7fa486c4515b804943e8d54e, MalwareBazaar) gets its C2 addresses from the A records of seris.gd, XOR-decoded with E7.70.8E.59; on 2026-10-10 seris.gd returned 41.205.42.92, which decodes to 206.189.164.5. Live sandbox run 2026-10-10 02:22-02:25 UTC with the bot steered to that record only: it connected to 206.189.164.5:44559 (random port per attempt, around 38000-47000), the server completed the handshake and held the session about 2.5 minutes while the bot sent keepalives and reports; no commands received. Delivered to our Cowrie telnet honeypot on 2026-10-09 18:07 UTC by 45.90.163.37 via http://176.65.139.40/tot. Confidence 100 = C2 accepted the bot live.