ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 49.0.248.230:2017.

Database Entry


IOC ID:278048
IOC: 49.0.248.230:2017
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Dofloo
Malware alias:AESDDoS
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
ASN:AS136907 HWCLOUDS-AS-AP
Country:- CN
First seen:2021-12-20 14:24:52 UTC
Last seen:never
UUID:986a40cf-61a0-11ec-8ab6-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:AESDDoS CVE-2021-44228 Dofloo log4j
Reference: https://bazaar.abuse.ch/sample/087b589c9fd7b934fe9c2a7711795165d8022e101983f9654de89c3125715929/

Avatar
abuse_ch
Rogue LDAP server used in log4j (CVE-2021-44228) exploitation attempts