ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 79.134.225.101:1012.

Database Entry


IOC ID:29358
IOC: 79.134.225.101:1012
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Nanocore RAT
Malware alias:Nancrat, NanoCore
Confidence Level : Confidence level is elevated (75%)
ASN:AS6775 FINK-TELECOM-SERVICES
Country:- CH
First seen:2021-05-05 14:21:59 UTC
Last seen:2023-09-27 18:39:07 UTC
UUID:411ca458-adad-11eb-a134-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:NanoCore
Reference: https://bazaar.abuse.ch/sample/ca7b06be1bfcfd7689710a2b92d80d16fcd00cc3a0f16d353dfd50c4252f0b76/

Avatar
abuse_ch
nanocore (aka Nancrat,NanoCore) botnet C2

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2021-05-06 06:06:18 5c53bb5c2d8a2d54637df1f9076b4647518a9609a80ad3b4c1bacde15c154e5e