Browse Botnet C&Cs

You are currently viewing the database entry for the Heodo botnet command&control server (C&C) 70.115.70.154. You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


Host:70.115.70.154
Hostname:cpe-70-115-70-154.gt.res.rr.com
Status:Offline
Spamhaus SBL:Not listed
Malware:Heodo -
AS number:AS11427
AS name:TWC-11427-TEXAS - Charter Communications Inc
Country:- US
First seen:2019-02-21 20:26:38 UTC
Last seen:2019-02-26 16:26:12 UTC

Malware Samples


The table below documents all malware samples associated with this Heodo botnet command&control server (C&C).

Timestamp (UTC)Malware Sample (MD5 hash)VTHostPortSignature
2019-02-26 16:58:01eaf7d57c526a5835e77a788d3ede3108Virustotal results 51/65 (78.46%) 70.115.70.15480ShipUp
2019-02-26 16:55:41ab772668257e81cf00d5291470f54581Virustotal results 21/51 (41.18%) 70.115.70.15480Heodo
2019-02-26 16:41:37b954ff715273edab9a30255289139fc9Virustotal results 21/51 (41.18%) 70.115.70.15480Heodo
2019-02-26 16:38:28baff7206fd6475e3f28a7a7d5cb8803fVirustotal results 23/54 (42.59%) 70.115.70.15480Heodo
2019-02-26 16:28:0504c49b54ff9029af84b1a8c62d34e9a8Virustotal results 13/56 (23.21%) 70.115.70.15480Heodo
2019-02-26 14:51:10c76726e3cdad1dcc075f116250a2fa78Virustotal results 11/50 (22.00%) 70.115.70.15480Heodo
2019-02-26 14:37:44dbaa235b2640cd860624c81822656002Virustotal results 22/52 (42.31%) 70.115.70.15480Heodo
2019-02-26 14:29:358948a89904d4477232a3baba747dc763Virustotal results 25/56 (44.64%) 70.115.70.15480Heodo
2019-02-21 20:40:522f832a5654dc7f5abe525e75357c24f6Virustotal results 35/59 (59.32%) 70.115.70.15480Heodo

# of malware samples: 9