Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 109.149.147.12 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:109.149.147.12
Hostname:host109-149-147-12.range109-149.btcentralplus.com
AS number:AS2856
AS name:BT-UK-AS BTnet UK Regional network
Country:- GB
First seen:2023-04-26 14:01:12 UTC
Last online:2023-04-27 16:xx:xx UTC

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusAbuse complaint sent?Last online (UTC)
2023-04-26 14:01:12109.149.147.122222
QakBot
Offline
Yes (2023-04-26 14:05:04 UTC)2023-04-27 16:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 109.149.147.12. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2023-05-03 21:43:10538a3337e6b94d88b52a24cd6a3a4b29DLL dllVirustotal results 62.32%
Quakbot
2023-05-03 21:41:310c4a0ee74f959e6be9e49305e17d3be4DLL dllVirustotal results 46.38%
Quakbot
2023-05-03 21:37:573113510f7c8a61fdc3565dd13dfa6d84DLL dllVirustotal results 57.97%
Quakbot
2023-05-03 21:21:053035cacfae030d6d76a5db183edf7592DLL dllVirustotal results 47.83%
Quakbot
2023-05-03 21:10:17cc9e8a018f6efaebc75f172ee4520329DLL dllVirustotal results 47.06%
Quakbot
2023-05-03 21:04:304dc2121a79f461baab4a1a1c959f5af1DLL dllVirustotal results 44.93%
Quakbot
2023-04-28 06:34:287006ab6ce6a25bbce00e1718bdad210dDLL dlln/a
Quakbot
2023-04-28 03:18:15c079bd5e8592242a689d11190fb8bdefDLL dlln/a
Quakbot
2023-04-27 05:28:18162c5d09f8407b10c4cc8d76f9d521c8DLL dllVirustotal results 18.84%
Quakbot