RedLineStealer botnet controller @62.182.156.183

The host at this IP address is obviously operated by cybercriminals. It is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse.

Malware botnet controller located at 62.182.156.183 on port 42926 TCP:
$ telnet 62.182.156.183 42926
Trying 62.182.156.183…
Connected to 62.182.156.183.
Escape character is ‘^]’

Referencing malware samples (MD5 hash):
6a4154428660607475bdc89fa44eda1c — AV detection: 23 / 68 (33.82%)
7c542f24adab5b1a737f581367dade2e — AV detection: 21 / 66 (31.82%)
7ce7ca272d7483e227286431d0767f2f — AV detection: 23 / 67 (34.33%)
845846e4baafed09da4dd20eb9aa5f39 — AV detection: 23 / 65 (35.38%)
8b4f36dfa0f8ba03018096bced9748c5 — AV detection: 23 / 68 (33.82%)
94d27d3ef200c37e07698119132e1cb8 — AV detection: 21 / 66 (31.82%)
a034e4f4d6908d41e08c36e54c2451f6 — AV detection: 39 / 63 (61.90%)
a485cb752e66e54c92ef00a9ae8f2eba — AV detection: 35 / 66 (53.03%)
a5c0c175bab8d32fcac148ded0d76f7b — AV detection: 23 / 53 (43.40%)
cb996bb8a1fc51ee08edd299a90bacfc — AV detection: 19 / 69 (27.54%)
ea6410c54b8ea167277ae92a049a7d6a — AV detection: 23 / 68 (33.82%)
eb04a9faa3ddb26885469709dc9fbb14 — AV detection: 24 / 67 (35.82%)

Опубликовано
В рубрике selectel.ru

Добавить комментарий

Ваш адрес email не будет опубликован. Обязательные поля помечены *