s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1931091 high

📛 Threat Title

Unknown malware: ip:port combination that is used for botnet Command&control (C&C) 134.122.204.114:8151

Category: Unknown malware Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: ip:port combination that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 100. Observed port: 8151. First seen: 2026-09-23 22:24:26 UTC. Reporter: devmihaylov. Tags: c2, Endpoint-Central, ManageEngine, RMM-abuse.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 134.122.204.114

IOC database

Type
ipv4
Value
134.122.204.114
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: ip:port combination that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 100. Observed port: 8151. First seen: 2026-09-23 22:24:26 UTC. Reporter: devmihaylov. Tags: c2, Endpoint-Central, ManageEngine, RMM-abuse.

  • External reference ThreatFox IOCs

Remediations (10)

  • web:executivegov.com

    ExecutiveGov

  • web:ijsrcseit.com

    301 Moved Permanently Moved Permanently The document has moved here.

  • web:owasp.org

    Summary Concurrent sessions are a common aspect of web applications that enable multiple simultaneous user interactions. This test case aims to evaluate the application's ability to handle multiple active sessions for a single user. This functionality is essential for effectively managing concurrent user sessions, particularly in sensitive areas such as admin panels containing Personally ...

  • web:pmc.ncbi.nlm.nih.gov

    We would like to show you a description here but the site won't allow us.

  • web:ro.ecu.edu.au

    The rebirthing suite modifies the original functionality, adds new functionality and inserts analysis avoidance techniques. The rebirthed malware could then be unleashed by the member machines of the botnet , at specified targets, in a controlled manner, under the direction of a Command and Control (C&C) infrastructure.

  • web:www.cisa.gov

    The CISA Vulnerability Bulletin provides a summary of new vulnerabilities that have been recorded in the past week. In some cases, the vulnerabilities in the bulletin may not yet have assigned CVSS scores. Vulnerabilities are based on the Common Vulnerabilities and Exposures

  • web:www.cisa.gov

    Summary Note: This joint Cybersecurity Advisory is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect ...

  • web:www.digitalphablet.com

    www.digitalphablet.com

  • web:www.pindrop.com

    Learn what spoofing is , how it works, the different types of spoofing attacks, and how to detect them using modern anti-spoofing technologies and voice security.

  • web:www.reddit.com

    We would like to show you a description here but the site won't allow us.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…