According to our telemetry and our own intelligence, the host at this IP address has been setup by cyber criminals for the exclusive purpose of hosting phishing sites, malware distribution sites and/or botnet controllers. We therefore advise our users to block any traffic from/to this IP address.
The host at this IP address is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.
Malware botnet controller at 141.8.199.238 port 443.
$ telnet 141.8.199.238 443
Trying 141.8.199.238…
Connected to 141.8.199.238.
Escape character is ‘^]’
Malicious domains observed at this IP address:
atom-softs.com. 600 IN A 141.8.199.238
atom-tw.com. 600 IN A 141.8.199.238
atom-tweak.net. 600 IN A 141.8.199.238
atomtweak.com. 600 IN A 141.8.199.238
atomtweaks.com. 600 IN A 141.8.199.238
banhamm.com. 600 IN A 141.8.199.238
beachbig.com. 600 IN A 141.8.199.238
best1488.com. 600 IN A 141.8.199.238
bethats.com. 600 IN A 141.8.199.238
blackinstalls.com. 600 IN A 141.8.199.238
bthuu.com. 600 IN A 141.8.199.238
chinett.com. 600 IN A 141.8.199.238
cloudjah.com. 600 IN A 141.8.199.238
cranonline.com. 600 IN A 141.8.199.238
dailykan.com. 600 IN A 141.8.199.238
djher.com. 600 IN A 141.8.199.238
far-lbs.com. 600 IN A 141.8.199.238
farlabed.com. 600 IN A 141.8.199.238
farlabus.com. 600 IN A 141.8.199.238
farlabweb.com. 600 IN A 141.8.199.238
freehar.com. 600 IN A 141.8.199.238
fuck-systems.com. 600 IN A 141.8.199.238
g-farlab.com. 600 IN A 141.8.199.238
geoshit.com. 600 IN A 141.8.199.238
getatomtweak.com. 600 IN A 141.8.199.238
getnek.com. 600 IN A 141.8.199.238
glclick.com. 600 IN A 141.8.199.238
gokaef.com. 600 IN A 141.8.199.238
gripeee.com. 600 IN A 141.8.199.238
gvnoweb.com. 600 IN A 141.8.199.238
i-farlab.com. 600 IN A 141.8.199.238
i-farlabs.com. 600 IN A 141.8.199.238
i-labspro.com. 600 IN A 141.8.199.238
in-softs.com. 600 IN A 141.8.199.238
it-farlab.com. 600 IN A 141.8.199.238
johnsol.com. 600 IN A 141.8.199.238
kayattr.com. 600 IN A 141.8.199.238
koren24.com. 600 IN A 141.8.199.238
labs-pr.com. 600 IN A 141.8.199.238
liveme202.com. 600 IN A 141.8.199.238
mindurl.com. 600 IN A 141.8.199.238
myfarlab.com. 600 IN A 141.8.199.238
nanbier.com. 600 IN A 141.8.199.238
netgul.com. 600 IN A 141.8.199.238
newfarlab.com. 600 IN A 141.8.199.238
nextinstall.info. 600 IN A 141.8.199.238
nongeeeeet.com. 600 IN A 141.8.199.238
noplayboy.com. 600 IN A 141.8.199.238
offtechnology.com. 600 IN A 141.8.199.238
onlinepleb.com. 600 IN A 141.8.199.238
ouclick.com. 600 IN A 141.8.199.238
payfilms.com. 600 IN A 141.8.199.238
pcrare.com. 600 IN A 141.8.199.238
proatomtweak.com. 600 IN A 141.8.199.238
royalyo.com. 600 IN A 141.8.199.238
sammore.com. 600 IN A 141.8.199.238
search1search.com. 600 IN A 141.8.199.238
sharemem.com. 600 IN A 141.8.199.238
soft-me.com. 600 IN A 141.8.199.238
softsme.com. 600 IN A 141.8.199.238
spiritualpay.top. 600 IN A 141.8.199.238
thepe.net. 600 IN A 141.8.199.238
thispacific-pact.top. 600 IN A 141.8.199.238
vrsrat.com. 600 IN A 141.8.199.238
wwwwcube.com. 600 IN A 141.8.199.238
yourkok.com. 600 IN A 141.8.199.238
zodomain.com. 600 IN A 141.8.199.238