Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 189.146.126.190 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:189.146.126.190
Hostname:dsl-189-146-126-190-dyn.prod-infinitum.com.mx
AS number:AS8151
AS name:Uninet S.A. de C.V.
Country:- MX
First seen:2022-03-30 17:42:24 UTC
Last online:2022-03-30 19:xx:xx UTC

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusAbuse compltain sent?Last online (UTC)
2022-03-30 17:42:24189.146.126.190443
QakBot
Offline
Yes (2022-03-30 17:45:03 UTC)2022-03-30 19:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 189.146.126.190. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2022-03-27 17:52:15e0d5e69ea223637be5fe0ecb5d80ad42DLL dllVirustotal results 13.43%
Quakbot
2022-03-27 17:52:067410c67ae0922c49cba8830ab0730dd7DLL dllVirustotal results 56.52%
Quakbot
2022-03-27 17:51:20ef68c313623fb62c136af175f37b7ef4DLL dllVirustotal results 41.18%
Quakbot
2022-03-27 17:51:1191e41d81a30d81d3dbb4b2e0940e53a8DLL dllVirustotal results 20.59%
Quakbot
2022-03-27 17:50:34e9de0e42adff55379ddeadda3e6f88c6DLL dllVirustotal results 59.09%
Quakbot
2022-03-27 17:50:025f377cc9c58aa08b2d54b58dc623edabDLL dllVirustotal results 52.94%
Quakbot
2022-03-27 17:48:259e2b3df7284dbd514c9248900f453b32DLL dllVirustotal results 40.30%
Quakbot