Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 197.94.84.128 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:197.94.84.128
Hostname:197-94-84-128.hff.mweb.co.za
AS number:AS10474
AS name:OPTINET
Country:- ZA
First seen:2022-09-20 14:11:10 UTC
Last online:2022-09-28 17:xx:xx UTC

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusAbuse compltain sent?Last online (UTC)
2022-09-20 14:11:10197.94.84.128443
QakBot
Offline
Yes (2022-09-20 14:15:09 UTC)2022-09-28 17:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 197.94.84.128. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2022-09-30 14:26:42fb3f760a7057f01408e9abaae71dd254isoVirustotal results 16.67%
Quakbot
2022-09-29 19:00:39d63aa7f38c0ae532200cf30c61f3fc02DLL dllVirustotal results 52.11%
n/a
2022-09-28 19:18:18c3879d55599e10d12e7fd7b4128a836aDLL dllVirustotal results 38.57%
n/a
2022-09-28 18:23:493b2113e5b32c2f5c629eab31a298d161isoVirustotal results 30.00%
n/a
2022-09-28 17:47:075fd969fd263d2a9caa30f4f3a0656852DLL dlln/a
n/a
2022-09-28 17:10:46fd54b5051d64a1e8fd65d99725f35a6fDLL dlln/a
n/a
2022-09-28 16:19:1944ee81238a82607f711237d670cb88b2DLL dlln/a
n/a
2022-09-28 16:19:11c54aa854dd769bdb588ddd9ecdcd907dison/a
n/a
2022-09-28 04:27:35e161560ca8671e85c534f25adb244a27zipn/a
n/a
2022-09-26 15:24:486d0d7e50918d6e7a30340223ed87292bison/a
Quakbot
2022-09-26 12:41:01e17ff4c8e0da566b6fbe6ce54101eee7DLL dlln/a
n/a
2022-09-26 12:40:4382001bafafda8b2ed449a35ea73b1d97ison/a
n/a
2022-09-22 16:47:56747a50a101b528a155c8095f1aef0230DLL dllVirustotal results 35.71%
Quakbot
2022-09-22 16:47:2407bff4971a0576d198d729cc697bd917isoVirustotal results 16.67%
Quakbot
2022-09-22 16:19:457a9e88520d046df19b302387f5b57d53isoVirustotal results 33.33%
Quakbot
2022-09-22 14:16:48e22a4ef15b7c6c9eb884e445cefa2ef9DLL dllVirustotal results 39.44%
Quakbot
2022-09-22 14:16:30a57ffd6724b8b316f9d14d9940650274ison/a
Quakbot
2022-09-22 14:09:3010d387700a0b7857f40070726226795fisoVirustotal results 20.00%
n/a
2022-09-22 14:08:578dbb05feeb1563cdc03c160b87d091adisoVirustotal results 20.00%
n/a
2022-09-21 16:33:33482a3d7a420b96a86c7cba3e05b5670bDLL dlln/a
n/a
2022-09-21 16:24:213fd6ff929bb62358cee961d45ff1471dDLL dlln/a
n/a
2022-09-21 09:13:03069fbff5bbfa4dd3295442b26893c6bbDLL dllVirustotal results 48.57%
Quakbot
2022-09-21 09:12:534987ea480e59ec96f6a8e4b5e4140a3fison/a
Quakbot
2022-09-20 15:51:1327d991cf1ecb8ddaa972fa4aeb03cb8bDLL dlln/a
n/a
2022-09-20 15:50:479f665545060568e4b7facdd639132ff3ison/a
Quakbot
2022-09-20 15:28:2948074eba4c3a7b9a7bf1aea1ae16ed9eisoVirustotal results 13.56%
Quakbot
2022-09-20 13:58:1637d2c73ff9e9e454259fa917faa9bff0DLL dllVirustotal results 14.49%
n/a
2022-09-20 13:57:43c0f6d661aa433a6451832401b1f58fe4ison/a
Quakbot