Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 109.218.108.3 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:109.218.108.3
Hostname:arennes-655-1-29-3.w109-218.abo.wanadoo.fr
AS number:AS3215
AS name:France Telecom - Orange
Country:- FR
First seen:2023-05-02 15:15:57 UTC
Last online:2023-05-03 17:xx:xx UTC

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusAbuse complaint sent?Last online (UTC)
2023-05-02 15:15:57109.218.108.32222
QakBot
Offline
Yes (2023-05-02 15:20:05 UTC)2023-05-03 17:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 109.218.108.3. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2023-05-24 04:00:33c2476efbe47c464242c2943ab9963f2cDLL dlln/a
Quakbot
2023-05-17 08:17:54a16d741f9b43438ee53ec6d9c14fca4fDLL dlln/a
Quakbot
2023-05-16 06:20:272eff350d7efaa5b0815700025f52bcf7DLL dlln/a
Quakbot
2023-05-12 07:00:41bfedf9836845c7b965b8b04b5fe54dafDLL dlln/a
Quakbot
2023-05-03 22:00:26d145866def44de1bb5594e46695acbfeDLL dllVirustotal results 27.54%
Quakbot
2023-05-03 21:32:27b462f9dc36eae8ad8189021ef295b3dfDLL dllVirustotal results 13.04%
Quakbot
2023-05-03 21:07:10b5f8377839b9a1e00e42087b9babe5dfDLL dllVirustotal results 10.14%
Quakbot
2023-05-03 21:04:40fd4fdbfc9d062e5e21988a6b55f6c2e6DLL dllVirustotal results 17.39%
Quakbot