TF-1812043
high
📛 Threat Title
Unknown malware: ip:port combination that delivery a malware payload 77.238.248.158:443
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: ip:port combination that delivery a malware payload. Attributed malware: Unknown malware. Confidence: 75. Observed port: 443. First seen: 2026-05-14 03:12:07 UTC. Reporter: Lenny_3BO. Tags: AEZA, ClickFix, hollow-host, midie, sectoprat-shared-infra, signed-veritas, VDSINA.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
77.238.248.158
IOC database
- Type
- ipv4
- Value
77.238.248.158- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that delivery a malware payload attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies a malware distribution server (payload delivery). IOC type: ip:port combination that delivery a malware payload. Attributed malware: Unknown malware. Confidence: 75. Observed port: 443. First seen: 2026-05-14 03:12:07 UTC. Reporter: Lenny_3BO. Tags: AEZA, ClickFix, hollow-host, midie, sectoprat-shared-infra, signed-veritas, VDSINA.
Remediations (6)
-
web:cybersec.gitguardian.com
We would like to show you a description here but the site won't allow us.
-
web:docs.sophos.com
Threat protection keeps you safe from malware , risky file types and websites, and malicious network traffic.
-
web:support.google.com
Note: If you use these advanced phishing and malware settings and dynamic email for your organization, learn how compliance rules are applied to dynamic messages. Advanced security settings Attachments —Protection against suspicious attachments and scripts from untrusted senders.
-
web:support.google.com
Email senders and marketers: Best practices for email sending If you send email to Gmail users, especially large amounts of mail, we recommend you follow best practices that help ensure your messages are delivered to Gmail's inbox. Follow these best practices to reduce the likelihood that Gmail blocks your messages or marks your messages as spam. Learn how to prevent mail to Gmail users from ...
-
web:www.reddit.com
We would like to show you a description here but the site won't allow us.
-
web:www.trendmicro.com
The installed malware is a .dll file protected with VMProtect. Using the other data file installed by the MSI package, it unpacks and manually loads different DLLs for its functionality. It also has a rootkit driver that is also unpacked from the data file and is used to hide its files, registry keys, and processes.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.