TF-1932772
high
📛 Threat Title
Unknown malware: ip:port combination that is used for botnet Command&control (C&C) 99.92.203.162:443
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: ip:port combination that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 75. Observed port: 443. First seen: 2026-09-25 09:47:29 UTC. Last seen: 2026-09-25 11:47:30 UTC. Reporter: abuse_ch. Tags: drb-ra, Mythic.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
99.92.203.162
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/99.92.203.162
IOC database
- Type
- ipv4
- Value
99.92.203.162- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/99.92.203.162
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: ip:port combination that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 75. Observed port: 443. First seen: 2026-09-25 09:47:29 UTC. Last seen: 2026-09-25 11:47:30 UTC. Reporter: abuse_ch. Tags: drb-ra, Mythic.
Remediations (10)
-
web:bazaar.abuse.ch
We would like to show you a description here but the site won't allow us.
-
web:community.fortinet.com
We would like to show you a description here but the site won't allow us.
-
web:community.fortinet.com
We would like to show you a description here but the site won't allow us.
-
web:cybersec.picussecurity.com
We would like to show you a description here but the site won't allow us.
-
web:news.google.com
We would like to show you a description here but the site won't allow us.
-
web:ro.ecu.edu.au
The rebirthing suite modifies the original functionality, adds new functionality and inserts analysis avoidance techniques. The rebirthed malware could then be unleashed by the member machines of the botnet , at specified targets, in a controlled manner, under the direction of a Command and Control (C&C) infrastructure.
-
web:rules.emergingthreats.net
We would like to show you a description here but the site won't allow us.
-
web:sentinelone.com
We would like to show you a description here but the site won't allow us.
-
web:www.cisa.gov
Home Page | CISA
-
web:www.cisa.gov
WASHINGTON - The Cybersecurity and Infrastructure Security Agency (CISA) published a malware analysis report today on FIRESTARTER, malware that allows remote access and control by malicious threat actors targeting Cisco Firepower and Secure Firewall products running Adaptive Security Appliance (ASA) or Firepower Threat Defense (FTD) software.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.