IOC Radar
MD5MediumSignal 100/100

297bec80a7bee340d10d4ea429909796

First Seen
Jun 23, 2025
Last Seen
Feb 9, 2026
Jun 23
First Seen
356d ago
Feb 9
Last Seen
125d ago
7
Reports
source reports
99%
Confidence
medium
Found in 7 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
MD5 Hash
MD5 file hash associated with malicious samples.
MISP Category
Artifacts Dropped
Hash Algorithm
MD5
Confidence
99%
Signal Score
100 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

67 techniques

Feed Intelligence Summary

7 reports99% confidence
7
Source reports
99%
Confidence score
Category tags
abuseactive scanningbotnetbotnet activitybotnet activity detectedbotnetsbrute forcebrute force attackbrute force attacksc2c2 communicationc2 servercommandcommand and controlcommunication protocolcompromised systemconnected devicescontrolcredential accesscredential stuffingctadata exfiltrationddosddos amplificationddos attackddos attacksddos reconnaissancedenial of servicedevice managementdistributed attacksdvrelfemmenhtal loaderevasionevasion techniquesexploitfile-hashfortiguard labsfortiguard webfour-faith routerftp brute forcehttp brute forcehttp ddoshttp scannerindicatorindustrial iotinitial compromiseinitial infectioninternet of thingsiot analyticsiot applicationsiot botnetiot devices targetediot platformsiot securityiot/ics attackipsips signaturelinuxlinux malwaremalicious softwaremalwaremalware deliverymalware distributionmalware loader activitymirai botnetmirai variantnetwork attacksnetwork protocolnetwork scanningnetwork securityoperating systempassword attackspayload deliverypayload downloadpersistence mechanismsprocess injectionprocess terminationprotocol exploitationreconnaissanceremote accessremote command executionremote servicesresearchedrouterscanning activitysecurity operationsservicesmart devicessmtp brute forcessh attackt1010t1021t1021.001t1027t1027.002t1027.004t1036t1036.005t1036.007t1040t1041t1053t1053.005t1055t1059t1059.003t1059.004t1059.005t1068t1069.001t1071t1071.001t1071.004t1076t1078t1082t1083t1087t1105t1106t1110t1110.001t1110.002t1110.003t1110.004t1140t1190t1204t1210t1485t1486t1496t1497t1497.001t1497.003t1498t1499.002t1499.003t1543t1546t1547t1547.001t1562t1563t1564t1565t1566t1566.001t1566.002t1571t1573.001t1583t1589t1595t1595.001t1595.002t1595.003tcp ddostcp protocolteamtelnet threatthreat intelligencetraffic mimicryudp ddosupnpvulnerabilitiesweb trafficxor encoding

Activity Timeline

1 total obs
Feb 9Feb 9

Threat Activity Heatmap

· Peak: 2026-02-09
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreHigh Risk
100
SIGNAL
Signal Score
99%
Confidence
7
Reports
First seenJun 23, 2025
Last seenFeb 9, 2026

VirusTotal

Not checked

WHOIS

references
https://www.fortinet.com/blog/threat-research/rondobox-unveiled-breaking-down-a-botnet-threat

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 11 months ago · Last seen 4 months ago
Appeared in 7 threat reports