ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 185.29.8.57:2022.

Database Entry


IOC ID:553280
IOC: 185.29.8.57:2022
IOC Type :ip:port
Threat Type :botnet_cc
Malware: STRRAT
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS60567 RixHost
Country:- EE
First seen:2022-05-12 17:40:06 UTC
Last seen:never
UUID:8fbdf7b4-d21a-11ec-ae87-42010aa4000a
Reporter AndreGironda
Reward 5 credits from ThreatFox
Tags:STRRAT
Reference: https://tria.ge/220512-vwlweshcaq

Avatar
AndreGironda
MITRE T1566.002
Date: Thu, 12 May 2022 19:30-20:00 +0300
Received: from vm450642.stark-industries.solutions (185.250.148.242)
Message-Id: <202205121646.24CGkGCe024341@vm450642.stark-industries.solutions>
Mime-Version: 1.0
From: "eRev, Inc <quickbooks@notification.intuit.com>"
ReplyTo:
Subject: Invoice from eRev Inc
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: base64
Return-Path: root@vm450642.stark-industries.solutions
Message Body URL: hXXps://agrouphostning.pages[.]dev/PAYMENT_RECEIPT_INV8938464944.zip
Downloaded Zipfile Name: PAYMENT_RECEIPT_INV8938464944.zip
Zipfile SHA256: 65caf68cce79fa953e7fea1f7be0ee3e14104f23ea16c10560fb9af9617ce4eb
Unzipped Data File Name: PAYMENT_RECEIPT_INV8938464944.jar
Data File SHA256: e3be7066e6922d7460dea80ca5b7fef8f4abc7b1f056d8f329c03b306e8ca9b0
Carved Java Archive File SHA256: 03b029a198a9eba2c91ab9940267ea12d48dd41326e7681b85dff13ba754aa89
Loaded DLL SHA256: a66959bec2ef5af730198db9f3b3f7cab0d4ae70ce01bec02bf1d738e6d1ee7a

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2022-05-16 12:11:25 2a8adf70bd23802e4df9a58f4f42567266abb923aa9e35c16473c9b657ca44cc