Browse Botnet C&Cs

You are currently viewing the database entry for the Heodo botnet command&control server (C&C) 158.174.130.145. You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


Host:158.174.130.145
Hostname:h-130-145.A465.priv.bahnhof.se
Status:Offline
Spamhaus SBL:Not listed
Malware:Heodo -
AS number:AS8473
AS name:BAHNHOF http://www.bahnhof.net/
Country:- SE
First seen:2019-01-22 16:05:29 UTC
Last seen:2019-01-24 20:32:40 UTC

Malware Samples


The table below documents all malware samples associated with this Heodo botnet command&control server (C&C).

Timestamp (UTC)Malware Sample (MD5 hash)VTHostPortSignature
2019-01-24 21:25:466a70c414e267e3136633d1d0746f513fVirustotal results 24/59 (40.68%) 158.174.130.14520Heodo
2019-01-24 20:42:44c6ec17f1f24369c1607bf810f05199cdVirustotal results 17/70 (24.29%) 158.174.130.14520Heodo
2019-01-24 18:00:4271a5aa74eb7f73baf71ba5c65cca7d45Virustotal results 25/56 (44.64%) 158.174.130.14520Heodo
2019-01-24 15:43:06b806811a5c910bb88b8d167374dec632Virustotal results 45/70 (64.29%) 158.174.130.14520Heodo
2019-01-23 09:24:470f41262fc7ef36bb47116ae8a3aa9046Virustotal results 18/71 (25.35%) 158.174.130.14520Heodo
2019-01-22 21:22:53f60099c26cf13cd06e945c2a41a26cc4Virustotal results 12/56 (21.43%) 158.174.130.14520Heodo
2019-01-22 17:52:196b39289b0fdb68499c27b4844eb8855eVirustotal results 23/57 (40.35%) 158.174.130.14520Heodo
2019-01-22 16:14:411912d8dd2666969016bb7a67b66b5646Virustotal results 18/71 (25.35%) 158.174.130.14520Heodo

# of malware samples: 8