54.91.129.132

Classification: Malicious

54.91.129.132 is a malicious IP address. Linked to Grandoreiro malware. Reported by 1 threat source, last seen 2026-08-11.

Current activity

  • Command & Control server — Used by cybercriminals to control victim computers.

MITRE ATT&CK associations

Malware families: GRANDOREIRO (S0531)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Grandoreiro ThreatFox Abuse.ch 2026-08-11 12:59:45 2026-08-11 13:25:04 botnet malicious-activity S0531 Grandoreiro

Tags

port:4403 grandoreiro port:5074 port:41694 geo mex

Whois information

AS name
AS14618 Amazon Data Services Northern Virginia
Registrant
Amazon Data Services Northern Virginia
City
Washington
State
DC
Postal code
20005
Country
US — United States 🇺🇸
First indexed
2026-08-11 13:25:04
Last updated
2026-08-11 13:25:04