Emotet malware distribution @87.236.16.79 [compromise website]

The host at this IP address is hosting a website that have been compromised by threat actors to distribute Emotet (aka Heodo) malware. The following URL is hosting a webshell that is being accessed by the threat actors programmatically to place malware on the website:

URL: http://lifenv.ru/hmof.php
Host: lifenv.ru
IP address: 87.236.16.79
Hostname: ssl.fox.beget.com

Опубликовано
В рубрике beget.ru

Добавить комментарий

Ваш адрес email не будет опубликован. Обязательные поля помечены *