RaccoonStealer botnet controller @176.58.98.13

The host at this IP address is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.

RaccoonStealer botnet controller located at 176.58.98.13 on port 80 (using HTTP POST):
hXXp://176.58.98.13/

$ nslookup 176.58.98.13
176-58-98-13.ip.linodeusercontent.com

Referencing malware binaries (MD5 hash):
bf21f20b191d0323e7e603d10033f926 — AV detection: 42 / 70 (60.00)
e86f1cd73f0be7895872a04dcdfb7766 — AV detection: 42 / 68 (61.76)
eb0197c366e0fb249c9267439870a10d — AV detection: 44 / 68 (64.71)
ecc4f90152ef8dd2e97a546c39d4548f — AV detection: 30 / 69 (43.48)
edd23746fbbbb426169894c868569eef — AV detection: 47 / 71 (66.20)
f05c36e5371738b4b50d20468b8fc548 — AV detection: 32 / 71 (45.07)

Опубликовано
В рубрике linode.com

Добавить комментарий

Ваш адрес email не будет опубликован. Обязательные поля помечены *