ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 194.5.98.250:1012.

Database Entry


IOC ID:5802
IOC: 194.5.98.250:1012
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Nanocore RAT
Malware alias:Nancrat, NanoCore
Confidence Level : Confidence level is elevated (75%)
ASN:AS149020 WEBHORIZON-AS-AP
Country:- IN
First seen:2021-03-29 13:55:36 UTC
Last seen:2023-09-27 18:41:17 UTC
UUID:7032ad9f-9096-11eb-858b-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:NanoCore
Reference: https://bazaar.abuse.ch/sample/a9dd5583f75c18a915745ca35e8331a0bdd7b2fb4eb5f072430a97515d521632/

Avatar
abuse_ch
nanocore (aka Nancrat,NanoCore) botnet C2

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2021-03-30 08:30:50 7a6e483857e7738d345256d4c17e2f3a14eb70bff468b84244271a902b545a75
2021-03-29 21:05:58 a2cdd57742b2a5b76d9b385c249e3f267f049b8029a39f3aad4110ac7b9fd9c4