Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 197.89.128.212 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:197.89.128.212
Hostname:197-89-128-212.dsl.mweb.co.za
AS number:AS10474
AS name:OPTINET
Country:- ZA
First seen:2022-06-03 05:01:39 UTC
Last online:2022-06-03 14:xx:xx UTC

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusAbuse compltain sent?Last online (UTC)
2022-06-03 05:01:39197.89.128.212443
QakBot
Offline
Yes (2022-06-03 05:05:02 UTC)2022-06-03 14:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 197.89.128.212. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2022-06-06 17:00:459d9d956a76ba9152518c71d9e416ab14DLL dlln/a
n/a
2022-06-05 16:59:48d94f0fb760eceb56010aff16fa939e7bDLL dlln/a
n/a
2022-06-03 10:30:284966912574b4148d9cb79d46b8bda7dfDLL dllVirustotal results 41.18%
n/a
2022-06-03 07:15:2622a5e0e51317e6c623eb3880a86b1eb9DLL dlln/a
n/a
2022-06-03 06:59:1739d94e3683378822c66169fbdcc993a6DLL dlln/a
n/a
2022-06-03 06:43:48da8fae91ca6c1454751747ebdcbcfae7DLL dlln/a
n/a
2022-06-03 06:24:490612a917da7e7f287debdb311b168f9bDLL dlln/a
n/a
2022-06-02 17:32:521399ec5699060949d5f83201e09380f1DLL dllVirustotal results 39.06%
n/a
2022-06-02 14:47:02ef08d0e213b3306b306ee41b37328a45DLL dllVirustotal results 41.18%
n/a
2022-06-02 14:46:42f4da7aa74564f424788cdb40f34ee61fDLL dllVirustotal results 33.82%
n/a