Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 91.191.172.124 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:91.191.172.124
Hostname:mail-mx.kureselnetmail.com
AS number:AS43391
AS name:NETDIREKT-AS
Country:- TR
First seen:2021-06-21 13:00:34 UTC
Last online:2021-09-08 08:xx:xx UTC

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusAbuse compltain sent?Last online (UTC)
2021-06-21 13:00:3491.191.172.12413783
Dridex
Offline
No2021-09-08 08:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 91.191.172.124. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2021-07-16 20:50:4222f5bc68d8200bc4888ea8ef7d1794c0Executable exeVirustotal results 75.71%
Dridex
2021-07-15 18:14:26c5d479040dc49534c86aa01468f57765Executable exeVirustotal results 69.12%
Dridex
2021-06-25 02:04:16a100fa797dce8e731b1267fef6c8e07dExecutable exeVirustotal results 66.67%
Dridex
2021-06-20 17:24:03e084ee4e2684a54293fb637254d3cc7cExecutable exeVirustotal results 65.22%
Dridex