Browse Botnet C&Cs

You are currently viewing the database entry for the Heodo botnet command&control server (C&C) 172.98.243.40. You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


Host:172.98.243.40
Hostname:dynamic172-98-243-40.caprock-spur.com
Status:Offline
Spamhaus SBL:Not listed
Malware:Heodo -
AS number:AS46849
AS name:TLSN-TX - TEXAS LONE STAR NETWORK, LLC
Country:- US
First seen:2019-02-22 12:19:36 UTC
Last seen:2019-03-06 00:47:21 UTC

Malware Samples


The table below documents all malware samples associated with this Heodo botnet command&control server (C&C).

Timestamp (UTC)Malware Sample (MD5 hash)VTHostPortSignature
2019-03-06 23:46:3339752d08b7976e2d44bff7cd78f4d63eVirustotal results 43/71 (60.56%) 172.98.243.4080Heodo
2019-03-06 14:46:35ba18b7afbac1e568c3fc977aa7b40000Virustotal results 42/65 (64.62%) 172.98.243.4080Heodo
2019-03-05 14:25:524db30d9c6f3c4fa37747f98d96c80d5eVirustotal results 38/64 (59.38%) 172.98.243.4080Heodo
2019-03-01 11:32:05f804d5467feec9a6612e1b2e22c5ad04Virustotal results 15/63 (23.81%) 172.98.243.4080Heodo
2019-02-26 16:55:41ab772668257e81cf00d5291470f54581Virustotal results 21/51 (41.18%) 172.98.243.4080Heodo
2019-02-26 16:41:37b954ff715273edab9a30255289139fc9Virustotal results 21/51 (41.18%) 172.98.243.4080Heodo
2019-02-26 16:38:28baff7206fd6475e3f28a7a7d5cb8803fVirustotal results 23/54 (42.59%) 172.98.243.4080Heodo
2019-02-26 16:28:0504c49b54ff9029af84b1a8c62d34e9a8Virustotal results 13/56 (23.21%) 172.98.243.4080Heodo
2019-02-26 16:26:175cdfd7f0918cc6b4943ac45b5c65e2a0Virustotal results 10/58 (17.24%) 172.98.243.4080Heodo
2019-02-26 10:57:216e9d8f99ec5f804e3d55135c3f9e5c48Virustotal results 23/69 (33.33%) 172.98.243.4080Heodo
2019-02-22 12:39:5118dd0e6db6d6b3451f48f832a59fbc4bVirustotal results 15/65 (23.08%) 172.98.243.4080Heodo

# of malware samples: 11