Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 217.165.85.223 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:217.165.85.223
Hostname:bba190469.alshamil.net.ae
AS number:AS5384
AS name:EMIRATES-INTERNET Emirates Internet
Country:- AE
First seen:2022-09-14 12:24:56 UTC
Last online:2022-09-16 07:xx:xx UTC

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusAbuse complaint sent?Last online (UTC)
2022-09-14 12:24:56217.165.85.223993
QakBot
Offline
Yes (2022-09-14 12:25:05 UTC)2022-09-16 07:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 217.165.85.223. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2022-10-06 12:27:03168c5cbb72c607c4bf81afe2c9628d5eisoVirustotal results 36.07%
n/a
2022-09-23 09:15:20dc7093386557fbb211e1a86b557f74aeDLL dllVirustotal results 54.93%
n/a
2022-09-16 17:13:59fc7120dfbd08e8330026e63b88ddd45aDLL dlln/a
n/a
2022-09-16 17:12:39124405e8f46a33ff523128b208c951d7DLL dlln/a
n/a
2022-09-16 17:12:2843a7e6abe10774f7b5dcdbc479e9742bison/a
n/a
2022-09-16 12:37:5151ba45a02291fa5af22c3183d11a3db3DLL dllVirustotal results 34.78%
n/a
2022-09-16 12:36:344a1389ea1b36c22d3999e1a349f6fe40ison/a
n/a
2022-09-15 19:36:44fbcdc3164e6fc424ab50d2e13fbaedfdDLL dlln/a
n/a
2022-09-15 19:36:3150ad8cabee08c42ffd42181835b2e83dison/a
n/a
2022-09-15 15:13:59baa6798c1674853f7dcf003b78ee79edDLL dllVirustotal results 27.54%
n/a
2022-09-15 15:13:481047eb62052e182c790ca11f900412f0ison/a
n/a
2022-09-14 17:20:480ff34513541f9c842a6df1358ab1c8dcDLL dlln/a
Quakbot
2022-09-14 12:59:3336b52522f8f7cdba7600d3d5c8a91966DLL dlln/a
Quakbot
2022-09-14 12:24:29838a66d6b19b82b219778a0e8a083815DLL dlln/a
n/a