AveMariaRAT botnet controller @192.95.0.200

The host at this IP address is obviously operated by cybercriminals. It is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.

Malware botnet controller located at 192.95.0.200 on port 6768 TCP:
$ telnet 192.95.0.200 6768
Trying 192.95.0.200…
Connected to 192.95.0.200.
Escape character is ‘^]’

$ nslookup 192.95.0.200
ip200.ip-192-95-0.net

Referencing malware samples:
MD5 e47a72f1a4ba1732f4a227f7569215c3
MD5 ea7d9d499457f32afcb7dafe3b3bb81c

Опубликовано
В рубрике ovh.net

Добавить комментарий

Ваш адрес email не будет опубликован.