ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 185.140.53.159:5672.

Database Entry


IOC ID:839091
IOC: 185.140.53.159:5672
IOC Type :ip:port
Threat Type :botnet_cc
Malware: NjRAT
Malware alias:Bladabindi, Lime-Worm
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS152586 KUROIT-AS-AP
Country:- GB
First seen:2022-07-22 12:30:16 UTC
Last seen:2023-09-27 14:03:13 UTC
UUID:0adaf883-09ba-11ed-baf1-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:njrat

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2022-07-23 07:00:05 668aaf533c64c79626595e74fbd9c1169178b286bb0dfbfbab24ef5ac48f8647
2022-07-23 06:55:05 e3f2213250dc7d0adcf052b29a087e04adac285c26590270a75ad587d10ae2df
2022-07-23 04:35:04 5dd6c84ff0c8efb68221b03b165ad150c58963f65e50fbe64f56b654d3399940
2022-07-22 12:30:17 e9fc051590c634e1fe8bbe06f0e8d4c949748a57b0ec89120f149beef1d85502