Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 197.89.17.146 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:197.89.17.146
Hostname:197-89-17-146.dsl.mweb.co.za
AS number:AS10474
AS name:OPTINET
Country:- ZA
First seen:2022-05-13 11:05:25 UTC
Last online:2022-05-13 14:xx:xx UTC

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusAbuse complaint sent?Last online (UTC)
2022-05-13 11:05:25197.89.17.146443
QakBot
Offline
Yes (2022-05-13 11:10:06 UTC)2022-05-13 14:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 197.89.17.146. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2022-05-17 12:31:06524026917551622d6f915d4066638bfaDLL dllVirustotal results 54.41%
Quakbot
2022-05-16 17:24:148a56eb21fe347dede3932571976bd824DLL dlln/a
n/a
2022-05-15 18:59:01a8eb5b2897a2c43c2beb607d081f99ceDLL dllVirustotal results 55.88%
n/a
2022-05-13 13:46:21a4a1c61dbaf4465bd31b41b0438edce9DLL dlln/a
n/a
2022-05-13 13:45:57b61a0ff82cb65dcf2ff44ab5b373742cDLL dlln/a
n/a
2022-05-13 13:44:1567adf3f7e4c2d711cf05dde69c807b69DLL dlln/a
n/a
2022-05-13 13:43:0893e0f94754d42c9ba469f484e2aa16d9DLL dlln/a
n/a
2022-05-13 13:09:18634b2f0ec318b9583db4c4112e709355DLL dlln/a
n/a
2022-05-13 13:08:455cbe546ac34eec3f4584b833cc5f7a10DLL dlln/a
n/a
2022-05-13 10:44:11acf51b5e99df18b841deb9c750db64feDLL dlln/a
n/a