Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 109.159.118.65 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:109.159.118.65
Hostname:host109-159-118-65.range109-159.btcentralplus.com
AS number:AS2856
AS name:BT-UK-AS BTnet UK Regional network
Country:- GB
First seen:2023-04-05 12:42:06 UTC
Last online:2023-04-09 21:xx:xx UTC

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusAbuse complaint sent?Last online (UTC)
2023-04-05 12:42:06109.159.118.652222
QakBot
Offline
Yes (2023-04-05 12:45:04 UTC)2023-04-09 21:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 109.159.118.65. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2023-05-03 21:58:02c30ee6912bdbc699947bee86c5ca8437DLL dllVirustotal results 66.67%
Quakbot
2023-05-03 21:55:478a7b54904f5cdf81572590f0892ec4fcDLL dllVirustotal results 68.12%
Quakbot
2023-05-03 21:23:3248eccfeb3130cf431341c3ce70b43299DLL dllVirustotal results 65.22%
Quakbot
2023-04-26 04:51:283a6f4295898c338072d040b2deb60f6dDLL dllVirustotal results 64.29%
Quakbot
2023-04-26 04:48:00aa6ffeb36a6180a5a06773829995d5b7DLL dllVirustotal results 57.14%
Quakbot
2023-04-24 03:13:054d86ca01b2e944c06bb0fb8188adec73DLL dlln/a
Quakbot
2023-04-22 11:09:448a05b9e5c68eb567898a87771f363398DLL dlln/a
Quakbot
2023-04-14 05:48:04fb6dfa2e825d7e7a899e08b2ebb955a0DLL dlln/a
Quakbot
2023-04-09 06:14:06efc870551e0de96e1720f1cf4c1b9ab1DLL dllVirustotal results 58.57%
Quakbot
2023-04-07 05:35:241ba4b14eef667bdb588d9f249855f7bbDLL dllVirustotal results 51.52%
Quakbot
2023-04-06 05:54:38db759f0aa7b22e2ccedefd2148d897a9DLL dllVirustotal results 11.43%
Quakbot