52.41.190.254

Classification: Malicious

52.41.190.254 is a malicious IP address. Linked to Poshc2 malware. Reported by 1 threat source, last seen 2026-08-26.

Current activity

  • Command & Control server — Used by cybercriminals to control victim computers.

MITRE ATT&CK associations

Malware families: POSHC2 (S0378)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
PoshC2 ThreatFox Abuse.ch 2026-08-26 19:46:23 2026-08-26 20:25:05 botnet malicious-activity S0378 PoshC2

Tags

port:443 poshc2 drb-ra

Whois information

AS name
AS16509 Amazon Technologies Inc.
Registrant
Amazon Technologies Inc.
City
Boardman
State
OR
Postal code
97818
Country
US — United States 🇺🇸
First indexed
2026-08-26 20:25:05
Last updated
2026-08-26 20:25:05