Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 104.236.52.89 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:104.236.52.89
Hostname:n/a
AS number:AS14061
AS name:DIGITALOCEAN-ASN
Country:- US
First seen:2021-01-21 10:00:28 UTC
Last online:2021-01-26 08:xx:xx UTC
Malware:Emotet

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusLast online (UTC)
2021-01-21 10:00:28104.236.52.898080
Emotet
Offline
2021-01-26 08:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 104.236.52.89. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2021-01-05 12:29:100099ed5a4a8e518f32679ac8e6ee7184DLL dlln/a
Heodo
2021-01-05 10:46:34ae42dad5e06ccfae6d803b797f9800b7DLL dlln/a
Heodo
2020-12-29 17:14:474dc15d89cf38278df51de3ecbf6c6d76Word file docn/a
Heodo
2020-07-23 08:53:083a22faa62fe39d42fd401c788aee6d79Executable exeVirustotal results 22.22%
Heodo
2020-07-18 08:49:380bb7fea100334884de78bb4902fac696Executable exen/a
Heodo
2020-07-18 04:33:0253c6a89b9d058935c839d07aeccb5fdeExecutable exen/a
Heodo
2020-07-17 18:40:11b6823c01bfd11eae2b8a690a8745aaf5Executable exeVirustotal results 16.67%
Heodo