DCRat botnet controller @51.91.193.177

The host at this IP address is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.

DCRat botnet controller located at 51.91.193.177 on port 80 (using HTTP GET):
hXXp://51.91.193.177/uploads/requestApidblinuxCdn.php

$ nslookup 51.91.193.177
2-i7-6700k-w-2-hosted-by.hshp.ovh

Referencing malware binaries (MD5 hash):
58cfa3457f3b836c80deee4ca88e49c0 — AV detection: 39 / 65 (60.00)
939ee300c70baf644fb57b5d956d02d6 — AV detection: 21 / 68 (30.88)
9884f13df8b19b9f16ad9eab7c4d411b — AV detection: 24 / 68 (35.29)
9c7adc45cf73dd66cbd6f9cee81f0bb9 — AV detection: 26 / 69 (37.68)
a6cfb10c2d19aedfd94c7ebe64af00d7 — AV detection: 20 / 63 (31.75)
b1f117279a9bfb4feda8f952e4da8b64 — AV detection: 33 / 68 (48.53)

Опубликовано
В рубрике ovh.net

Добавить комментарий

Ваш адрес email не будет опубликован. Обязательные поля помечены *