ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 79.134.225.30:1144.

Database Entry


IOC ID:7287
IOC: 79.134.225.30:1144
IOC Type :ip:port
Threat Type :botnet_cc
Malware: Nanocore RAT
Malware alias:Nancrat, NanoCore
Confidence Level : Confidence level is elevated (75%)
ASN:AS6775 FINK-TELECOM-SERVICES
Country:- CH
First seen:2021-04-08 06:10:37 UTC
Last seen:2023-09-27 18:37:58 UTC
UUID:2363086b-9831-11eb-858b-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:NanoCore
Reference: https://bazaar.abuse.ch/sample/dd812fc747a7e389fd641eff10517478feef81056c21582061db8c3e2e7173f1/

Avatar
abuse_ch
nanocore (aka Nancrat,NanoCore) botnet C2

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2021-04-09 08:05:25 20e490afba639ea251a2f095a8b9b85e1b9922ff6d8b6f47ceb567ba62521a28
2021-04-09 07:45:26 f542bc0175168daa808ce1448a019f88b058df6d0702c6daa4a0f83a481f2a5e