ThreatFox IOC Database

You are viewing the ThreatFox database entry for ip:port 5.252.118.34:37991.

Database Entry


IOC ID:851289
IOC: 5.252.118.34:37991
IOC Type :ip:port
Threat Type :botnet_cc
Malware: RedLine Stealer
Malware alias:RECORDSTEALER
Confidence Level : Confidence level is high (100%)
ASN:AS210644 AEZA-AS
Country:- RU
First seen:2022-09-23 10:15:44 UTC
Last seen:2023-08-01 18:03:39 UTC
UUID:af9d05cf-3b28-11ed-ae73-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:RedLineStealer

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2022-09-23 10:20:42 ca81d370ff7e2f2b429d2c1ff109a351f66f5bb9799d34c424aaaac684ed59a4
2022-09-23 10:15:51 060a8a1f76a32fe8e252dc9bcb31f6a5eeb8bffff0ff1cccbf224a31c9fb0f97