Browse Botnet C&Cs

You are currently viewing the database entry for the Heodo botnet command&control server (C&C) 149.202.153.251. You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


Host:149.202.153.251
Hostname:srv-web2.ffconsulting.com
Status:- Online
Spamhaus SBL:SBL459006
Malware:Heodo -
AS number:AS16276
AS name:OVH
Country:- FR
First seen:2019-09-12 16:06:13 UTC
Last seen:2019-11-21 00:11:14 UTC
Last online:2019-12-08

Malware Samples


The table below documents all malware samples associated with this Heodo botnet command&control server (C&C).

Timestamp (UTC)Malware Sample (MD5 hash)VTHostPortSignature
2019-11-21 12:46:358756b4152bb19962c8d5922010915275Virustotal results 10 / 70 (14.29%) 149.202.153.2518080Heodo
2019-11-21 12:46:358756b4152bb19962c8d5922010915275Virustotal results 10 / 70 (14.29%) 149.202.153.2518080Heodo
2019-11-21 12:46:358756b4152bb19962c8d5922010915275Virustotal results 10 / 70 (14.29%) 149.202.153.2518080Heodo
2019-10-20 18:40:44d15a49a831ecad633bee0558aee77517Virustotal results 32/55 (58.18%) 149.202.153.2518080Heodo
2019-10-20 13:36:30339afcba99fadf82600586bf10741802n/a149.202.153.2518080Heodo
2019-09-23 12:58:21ba66ff3aa6e56883508e756fcf6174ddVirustotal results 49/70 (70.00%) 149.202.153.2518080Heodo
2019-09-19 07:06:53fff1f8303c1896545b81d35ca2cec825Virustotal results 9 / 71 (12.68%) 149.202.153.2518080Heodo
2019-09-18 05:24:1068672a39118e8524c9239dca65a13a08Virustotal results 53/69 (76.81%) 149.202.153.2518080Heodo
2019-09-18 04:19:018536dfa39245d95c60dcfb91a43b07bbVirustotal results 22 / 70 (31.43%) 149.202.153.2518080Heodo
2019-09-18 03:22:25cacce37b4a680c8ac95ca32a286cdf66Virustotal results 47/69 (68.12%) 149.202.153.2518080Heodo
2019-09-18 03:04:174d2bb5a87151ab1d176911f7404024f6Virustotal results 52/69 (75.36%) 149.202.153.2518080Heodo
2019-09-18 03:00:26d55a1a33ff66c8e4bb06f60b8c689894Virustotal results 51/67 (76.12%) 149.202.153.2518080Heodo
2019-09-18 02:18:159a586dc8457821fc650be4e777a76a92Virustotal results 51/69 (73.91%) 149.202.153.2518080Heodo
2019-09-18 01:22:046021f7fdce6de901934081273ab028deVirustotal results 16 / 70 (22.86%) 149.202.153.2518080Heodo

# of malware samples: 14