ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 138.201.135.172:3981.

Database Entry


IOC ID:428430
IOC: 138.201.135.172:3981
IOC Type :ip:port
Threat Type :botnet_cc
Malware: RedLine Stealer
Malware alias:RECORDSTEALER
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS24940 HETZNER-AS
Country:- DE
First seen:2022-03-20 22:42:40 UTC
Last seen:2023-08-01 17:56:53 UTC
UUID:0c6d4a76-a89f-11ec-8129-42010aa4000a
Reporter fish_illuminati
Reward 5 credits from ThreatFox
Tags:RedLineStealer
Reference: https://app.any.run/tasks/7357fa72-c1ff-4502-b725-1f1eb42bc400

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2022-03-29 14:34:10 86d66851e61d819a92186de68dce76955499d6d615e425b8a5924e6561c9b3ef