Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 134.35.9.144 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:134.35.9.144
Hostname:n/a
AS number:AS30873
AS name:PTC-YEMENNET
Country:- YE
First seen:2022-09-20 14:11:07 UTC
Last online:2022-09-20 15:xx:xx UTC

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusAbuse compltain sent?Last online (UTC)
2022-09-20 14:11:07134.35.9.144443
QakBot
Offline
Yes (2022-09-20 14:15:07 UTC)2022-09-20 15:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 134.35.9.144. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2022-09-21 16:33:33482a3d7a420b96a86c7cba3e05b5670bDLL dlln/a
n/a
2022-09-21 16:24:213fd6ff929bb62358cee961d45ff1471dDLL dlln/a
n/a
2022-09-20 15:51:1327d991cf1ecb8ddaa972fa4aeb03cb8bDLL dlln/a
n/a
2022-09-20 15:50:479f665545060568e4b7facdd639132ff3ison/a
Quakbot
2022-09-20 15:28:2948074eba4c3a7b9a7bf1aea1ae16ed9eisoVirustotal results 13.56%
Quakbot
2022-09-20 13:58:1637d2c73ff9e9e454259fa917faa9bff0DLL dllVirustotal results 14.49%
n/a
2022-09-20 13:57:43c0f6d661aa433a6451832401b1f58fe4ison/a
Quakbot