Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 173.81.4.147 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:173.81.4.147
Hostname:173-81-4-147.pkbgcmtk01.res.dyn.suddenlink.net
AS number:AS19108
AS name:SUDDENLINK-COMMUNICATIONS
Country:- US
First seen:2021-02-23 20:23:58 UTC
Last online:2021-04-06 18:xx:xx UTC
Malware:TrickBot

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusLast online (UTC)
2021-04-06 15:48:31173.81.4.147443
TrickBot
Offline
2021-04-06 18:xx:xx
2021-02-23 20:23:58173.81.4.147449
TrickBot
Offline
2021-03-04 15:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 173.81.4.147. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2021-03-21 20:39:44537da1366bb7e46383ca5fd8d1fc3b39Executable exeVirustotal results 37.14%
TrickBot
2021-03-15 21:50:128a9e09d3073c9ed73b9157cf8d807a4fExecutable exen/a
n/a
2021-03-14 19:53:3417b22bd89f5b9734de8cc5969164e6beExecutable exeVirustotal results 59.42%
TrickBot
2021-03-11 19:37:26d6044af624956d993958615a73b10e8cExecutable exeVirustotal results 47.69%
n/a
2021-03-09 20:14:37e45673ebc9c864582c9a080ad3ebf40fExecutable exeVirustotal results 40.85%
n/a
2021-03-09 20:13:11667dde9b95f59f81f3afca361896f075Executable exen/a
n/a
2021-03-09 05:45:540bf80a792bd7f7f9c12f3a6201dbae14Executable exen/a
TrickBot
2021-03-05 20:10:088d42ee406b8dc82c6bf6eb7cd4ba89ebExecutable exeVirustotal results 66.20%
TrickBot
2021-03-04 21:31:38b50a5ce5906a66241e751b6e5838a9d1Executable exeVirustotal results 68.57%
TrickBot
2021-03-01 13:40:285e3ac60f9af6bd3b89111fc54fb64293DLL dlln/a
TrickBot