ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 23.105.131.190:4040.

Database Entry


IOC ID:26796
IOC: 23.105.131.190:4040
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Nanocore RAT
Malware alias:Nancrat, NanoCore
Confidence Level : Confidence level is elevated (75%)
ASN:AS396362 LEASEWEB-USA-NYC
Country:- NL
First seen:2021-05-01 11:05:12 UTC
Last seen:2023-09-27 18:39:03 UTC
UUID:19c8148d-aa6d-11eb-a134-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:NanoCore
Reference: https://bazaar.abuse.ch/sample/abff9b1f07e8b7e7887b51a387e2c36438e04fe8de4b7488ef4917d26be0b36f/

Avatar
abuse_ch
nanocore (aka Nancrat,NanoCore) botnet C2

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2021-05-04 15:36:03 a5f9d3b38612d88169c4cf6f934a93fcf3bbd772f2f3e5ac1e4a7f0b4ce6d115