Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 81.190.193.197 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:81.190.193.197
Hostname:host-81-190-193-197.dynamic.mm.pl
AS number:AS21021
AS name:MULTIMEDIA-AS Cable DTV Internet Voice Provider in Poland.
Country:- PL
First seen:2021-12-09 06:44:42 UTC
Last online:2022-01-07 20:xx:xx UTC

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusAbuse compltain sent?Last online (UTC)
2021-12-09 06:44:4281.190.193.197443
TrickBot
Offline
Yes (2021-12-09 06:50:04 UTC)2022-01-07 20:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 81.190.193.197. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2021-12-30 04:11:195049847d7c91e1ae2a133d6856a63a75Executable exen/a
TrickBot
2021-12-29 07:05:093b6339c69fe0e4ad5d0013e66001d8bfExecutable exeVirustotal results 39.71%
TrickBot
2021-12-17 19:09:40747fb17f4e7376051aadd2f218fed747Executable exeVirustotal results 26.15%
TrickBot
2021-12-16 11:18:049ecb818212dac53f7a1db8bce3e5e2fcExecutable exen/a
TrickBot
2021-12-16 08:23:14df0bdb09d28e37a1783d270c84e1c533Executable exen/a
TrickBot
2021-12-16 07:12:1180e5764c1bda1dbd35829efdefaea845Executable exen/a
TrickBot
2021-12-12 06:00:428823fd25da299a222008dcfc94f91cdcDLL dllVirustotal results 53.03%
TrickBot
2021-12-11 04:11:002d9d4705303f85829c8311574e78061fDLL dlln/a
TrickBot
2021-12-10 02:08:105d1a1e4afb362e840f951ce7c611b686DLL dlln/a
TrickBot
2021-12-09 05:44:2806c080b825d568192227f9910b621a8dDLL dlln/a
TrickBot