Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 139.5.101.203 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:139.5.101.203
Hostname:n/a
AS number:AS58659
AS name:QCPL-IN Quest Consultancy Pvt Ltd
Country:- IN
First seen:2021-01-21 10:26:27 UTC
Last online:2021-01-25 13:xx:xx UTC
Malware:Emotet

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusLast online (UTC)
2021-01-21 10:26:27139.5.101.20380
Emotet
Offline
2021-01-25 13:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 139.5.101.203. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2021-03-01 20:47:20f79bbd37435653c1f918a9e652d0b197Executable exen/a
Heodo
2021-02-13 19:30:5432cb979fa5cd59a3527447a6680e1565Executable exen/a
Heodo
2021-02-06 19:52:189f21dc9a39adc180e1aed4ea95f376f3Executable exeVirustotal results 63.38%
Heodo
2021-02-04 21:25:46de249cb509d8a2106a92b71089093f68Executable exeVirustotal results 68.57%
Heodo
2021-02-01 21:28:32fd094f8ffdab2e4e6556a9670aa17ae2Executable exeVirustotal results 66.67%
Heodo
2021-01-26 01:45:58e709fd4e75cb6959c9d77bb0dda71d83DLL dlln/a
Heodo
2021-01-07 02:37:36192bd5df827ec598974f4506272b619dDLL dlln/a
Heodo
2021-01-06 14:58:13d1540b55475d6933d0b4b7102d00be9eDLL dlln/a
Heodo
2021-01-06 10:17:207242cf2c95d61c7f2655a29bb50fe81fDLL dlln/a
Heodo
2020-12-25 18:59:00aecfc3b78a1665115eb0b884daf45cebExecutable exeVirustotal results 50.72%
Heodo
2020-12-25 18:54:1629191efba92076c43806a65ab51c0f7cExecutable exeVirustotal results 50.00%
n/a
2020-12-20 18:32:0646045a93642b60ebfc2f26cebc28ffbcExecutable exen/a
Heodo