Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 103.9.36.172 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:103.9.36.172
Hostname:k8s-worker1.asyst.co.id
AS number:AS131710
AS name:IDNIC-AERONET-AS-ID PT Aero Systems Indonesia
Country:- ID
First seen:2021-12-31 03:47:39 UTC
Last online:2022-01-29 02:xx:xx UTC

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusAbuse compltain sent?Last online (UTC)
2021-12-31 03:47:39103.9.36.172443
Dridex
Online
Yes (2021-12-31 06:05:03 UTC)2022-01-29 02:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 103.9.36.172. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2022-01-06 12:57:15acc35eb9469a1b9680cbbd1aeb38f5daExecutable exeVirustotal results 62.32%
Dridex
2022-01-02 20:43:38ac30f1036fcadd1fcdf2926c03de5a02Executable exeVirustotal results 64.18%
Dridex
2022-01-02 09:12:38bdcc394fd0f779a51a8348bf60f26275Executable exeVirustotal results 67.65%
Dridex
2021-12-31 22:14:30c1c379fc0b9c4b5d83b75d1c6a6dde67Executable exeVirustotal results 52.94%
Dridex
2021-12-31 07:13:57a5eb3426e582795b6393a328cd27bf94Executable exeVirustotal results 60.29%
Dridex
2021-12-31 03:48:01ac77adb25c9c8175c189382b15a0bcdbExecutable exeVirustotal results 47.76%
Dridex
2021-12-31 03:35:03a24919ea7bfce78d50511bac92771d3dExecutable exeVirustotal results 52.24%
Dridex