s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

ipv4 172.94.18.103

📛 IOC Value

172.94.18.103

First seen: Last seen: Threats: 10 Source: AlienVaulkt OTXThreatFox IOCsThreatfox IOCs/Threats

Description

ip:port combination that is used for botnet Command&control (C&C) attributed to AsyncRAT

Found in 10 threats

Threat Title Severity Attached Source
TF-1921304 AsyncRAT: ip:port combination that is used for botnet Command&control (C&C) 172.94.18.103:78 high ThreatFox IOCs
TF-1920976 AsyncRAT: ip:port combination that is used for botnet Command&control (C&C) 172.94.18.103:74 high ThreatFox IOCs
TF-1877324 AsyncRAT: ip:port combination that is used for botnet Command&control (C&C) 172.94.18.103:77 high ThreatFox IOCs
TF-1843760 AsyncRAT: ip:port combination that is used for botnet Command&control (C&C) 172.94.18.103:70 high Threatfox IOCs/Threats
TF-1831611 AsyncRAT: ip:port combination that is used for botnet Command&control (C&C) 172.94.18.103:72 high Threatfox IOCs/Threats
TF-1829893 AsyncRAT: ip:port combination that is used for botnet Command&control (C&C) 172.94.18.103:71 high Threatfox IOCs/Threats
OTX-6a12872d60bd9bd24d16bf52 AsyncRAT - C2 IP/Domain Tracker - 2026-05-24 medium AlienVaulkt OTX
TF-1817873 AsyncRAT: ip:port combination that is used for botnet Command&control (C&C) 172.94.18.103:73 high Threatfox IOCs/Threats
TF-1817829 AsyncRAT: ip:port combination that is used for botnet Command&control (C&C) 172.94.18.103:75 high Threatfox IOCs/Threats
TF-1816209 AsyncRAT: ip:port combination that is used for botnet Command&control (C&C) 172.94.18.103:76 high ThreatFox IOCs

VirusTotal

16/89Vendors flagged
-12Community score
Last refreshed
↗ Open on VirusTotal https://www.virustotal.com/gui/ip-address/172.94.18.103

File details (from VirusTotal)

Network
172.94.18.0/24
Country
DE
AS owner
M247 Europe SRL
ASN
9009
Regional registry
RIPE NCC

History

Last analysis
2026-09-17 17:05 UTC
Last modified on VirusTotal
2026-09-17 17:43 UTC
WHOIS record date
2026-09-03 17:17 UTC

Flagged vendors — 16 / 89

  • loading…

Full list of vendors

  • loading…

VirusTotal details

loading…

IP reputation (AbuseIPDB · GreyNoise)

Verdict
clean
Abuse confidence
0 / 100
Reports
0 from 0
Checked
—

Internet Security - DE · Data Center/Web Hosting/Transit · DE

Providers unavailable: greynoise (rate limited)

MetaDefender reputation

1 / 20 Sources flagged
flaggedVerdict
Last checked

Flagged by: webroot.com

Country
Germany

Open the full MetaDefender report ↗

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

IP Geolocation

Loading…