Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 54.37.202.209 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:54.37.202.209
Hostname:web1.evosw.com
AS number:AS16276
AS name:OVH
Country:- FR
First seen:2021-10-27 15:37:56 UTC
Last online:2021-11-19 13:xx:xx UTC

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusAbuse compltain sent?Last online (UTC)
2021-10-27 15:37:5654.37.202.2098194
Dridex
Offline
Yes (2021-11-25 15:41:26 UTC)2021-11-19 13:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 54.37.202.209. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2021-11-03 18:55:3885af0726b87c0ebf3b66cf4530f43fe3Executable exeVirustotal results 54.41%
Dridex
2021-10-26 23:23:38b0361a0768fe5869e388312340bc35dcExecutable exeVirustotal results 59.42%
Dridex
2021-10-26 18:39:31ae8f03d7a3dcccd13420d0520a87e074Executable exeVirustotal results 59.42%
Dridex
2021-10-26 18:34:07aa7a1361feb49bdc9ae17efcd3510674Executable exeVirustotal results 69.12%
Dridex