RemcosRAT botnet controller @54.209.212.142

The host at this IP address is obviously operated by cybercriminals. It is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.

Malware botnet controller located at 54.209.212.142 on port 2030 TCP:
$ telnet 54.209.212.142 2030
Trying 54.209.212.142…
Connected to 54.209.212.142.
Escape character is ‘^]’

$ nslookup 54.209.212.142
ec2-54-209-212-142.compute-1.amazonaws.com

$ dig +short davidwongwarzone.zapto.org
54.209.212.142

Referencing malware samples (MD5 hash):
1034b0592238bb02bfa08d4817a3e5ed — AV detection: 7 / 69 (10.14%)

Опубликовано
В рубрике amazon.com

Добавить комментарий

Ваш адрес email не будет опубликован. Обязательные поля помечены *