ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 5.61.37.70:38427.

Database Entry


IOC ID:843371
IOC: 5.61.37.70:38427
IOC Type :ip:port
Threat Type :botnet_cc
Malware: RedLine Stealer
Malware alias:RECORDSTEALER
Confidence Level : Confidence level is high (100%)
ASN:AS28753 LEASEWEB-DE-FRA-10
Country:- NL
First seen:2022-08-15 21:20:37 UTC
Last seen:2023-08-01 18:03:43 UTC
UUID:1b2ddfd0-1ce0-11ed-ae73-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:RedLineStealer

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2022-08-15 23:35:34 a0e2c62c90c6c425bfd56fef3d1e04530a1b0fd0dbf693cae048fcd1647f3e03
2022-08-15 23:00:37 816ba07d828978228709f49586655c2c3a36171480a10c2e75b93aedc6ca4972
2022-08-15 22:50:36 4e6d6ad0794876deca4c2bb8d44d0c860feaa349df2d2d5e67265735f47a8ff4
2022-08-15 21:20:37 234aceb545ad876d83a18d1c882e2b24b39607387fd413a718ca65befec5f015