DCRat botnet controller @82.146.48.223

The host at this IP address is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.

DCRat botnet controller located at 82.146.48.223 on port 80 (using HTTP GET):
hXXp://82.146.48.223/63/TrackGenerator/Phpjavascript0/SecureProtect0Base/defaultuniversalLocalcentralDownloads.php

$ nslookup 82.146.48.223
sq.hack.fvds.ru

Referencing malware binaries (MD5 hash):
6e4f52db7bfdadb99a8dfb7f1f6b9333 — AV detection: 29 / 69 (42.03)
7d8e9f911abd4a98855ba0ac37ae9396 — AV detection: 40 / 66 (60.61)
a117313aa67527dad47054aa6ad4d975 — AV detection: 48 / 71 (67.61)
ada065fa63b9758fd689237bbdd86f21 — AV detection: 42 / 68 (61.76)

Добавить комментарий

Ваш адрес email не будет опубликован. Обязательные поля помечены *