Browse Botnet C&Cs

You are currently viewing the database entry for the Heodo botnet command&control server (C&C) 105.184.109.189. You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


Host:105.184.109.189
Hostname:105-184-109-189.north.dsl.telkomsa.net
Status:Offline
Spamhaus SBL:Not listed
Malware:Heodo -
AS number:AS37457
AS name:Telkom-Internet
Country:- ZA
First seen:2019-04-08 11:54:48 UTC
Last seen:2019-06-13 07:01:50 UTC
Last online:2019-04-11

Malware Samples


The table below documents all malware samples associated with this Heodo botnet command&control server (C&C).

Timestamp (UTC)Malware Sample (MD5 hash)VTHostPortSignature
2019-06-13 07:34:31373709680a3ffae8928de19078b596d9Virustotal results 58/71 (81.69%) 105.184.109.189443Heodo
2019-06-13 07:34:22361ee1a460ccd5f7ff25c944968cef58Virustotal results 58/69 (84.06%) 105.184.109.189443Heodo
2019-06-13 07:20:5694974c975b8d8cb435358d4ddc60c831Virustotal results 55/66 (83.33%) 105.184.109.189443Heodo
2019-06-13 07:18:06da3fa81754ad90fd9ebade6929cf06b8Virustotal results 57/70 (81.43%) 105.184.109.189443Heodo
2019-04-15 18:23:47de4df0ddb74539e15bf65502734a2d10Virustotal results 51/68 (75.00%) 105.184.109.189443Heodo

# of malware samples: 5