ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 185.140.53.131:5723.

Database Entry


IOC ID:291628
IOC: 185.140.53.131:5723
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Nanocore RAT
Malware alias:Nancrat, NanoCore
Confidence Level : Confidence level is elevated (75%)
ASN:AS152586 KUROIT-AS-AP
Country:- GB
First seen:2022-01-06 21:22:14 UTC
Last seen:2023-09-27 18:37:30 UTC
UUID:b7a6a509-6f36-11ec-8ab6-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:NanoCore
Reference: https://bazaar.abuse.ch/sample/937f8a1fdba02c0f423af925d4820b23cdfa18dc82e46f76bd8ff9c121ef5022/

Avatar
abuse_ch
nanocore (aka Nancrat,NanoCore) botnet C2

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2022-01-07 07:05:57 937f8a1fdba02c0f423af925d4820b23cdfa18dc82e46f76bd8ff9c121ef5022