Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 144.91.80.228 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:144.91.80.228
Hostname:cloud.swiftspeed.org
AS number:AS51167
AS name:CONTABO
Country:- DE
First seen:2022-07-07 08:16:10 UTC
Last online:2022-07-07 13:xx:xx UTC

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusAbuse complaint sent?Last online (UTC)
2022-07-07 08:16:10144.91.80.2288080
Emotet
Offline
Yes (2022-07-07 08:20:04 UTC)2022-07-07 13:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 144.91.80.228. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2022-07-12 12:13:0731ad4b373a6bc92a490e967b76a736a6Word file xlsxn/a
SilentBuilder
2022-07-11 09:53:23d186c9943a5f22092eb4e1e4b3d8ee15Word file xlsVirustotal results 67.80%
Heodo
2022-07-08 11:50:45fdbfdf770d9b11baf026c5975545b8e4Word file xlsn/a
SilentBuilder
2022-07-07 13:10:21426b98833dfb8263f088234191a4599eDLL dlln/a
Heodo
2022-07-07 11:05:2942485075f589704e1cd24c8cb24c5758DLL dlln/a
Heodo
2022-07-07 10:35:54e293062ec5dcff77fde7da93ecd7f92dDLL dlln/a
Heodo
2022-07-07 08:56:03f84afd5234e9164d60958a987750ca96Word file xlsVirustotal results 54.24%
SilentBuilder
2022-07-07 08:09:58f476a81acc067b9469f9b2562489809cWord file xlsn/a
SilentBuilder