Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 71.31.232.65 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:71.31.232.65
Hostname:h65.232.31.71.dynamic.ip.windstream.net
AS number:AS7029
AS name:WINDSTREAM
Country:- US
First seen:2023-04-05 12:32:08 UTC
Last online:2023-04-15 20:xx:xx UTC

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusAbuse complaint sent?Last online (UTC)
2023-04-05 12:32:0871.31.232.65995
QakBot
Offline
Yes (2023-04-05 12:35:06 UTC)2023-04-15 20:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 71.31.232.65. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2023-04-28 10:10:088765e5a7654f4c706c5e0f2e2837afceDLL dlln/a
Quakbot
2023-04-13 08:46:15838ab8c602f6cdd930a0f003dbd28954DLL dlln/a
Quakbot
2023-04-08 07:00:33cf487714c58a387ae4bbd5a462266a7bDLL dllVirustotal results 58.57%
Quakbot
2023-04-07 05:36:377a3cccf70868d48c108dde5bd7326d01DLL dllVirustotal results 55.07%
Quakbot
2023-04-06 08:51:049333a0542a7a9b23092d7c8c21705d2cDLL dlln/a
Quakbot
2023-04-06 06:39:51e47f26dcede9748ff64469236e7df1d3DLL dlln/a
Quakbot
2023-04-06 05:50:4218e9258ac995abc88b168a65d027c7dfDLL dlln/a
Quakbot
2023-04-05 18:52:2616f2b3dd47643ef15f53fb4dc1edbda9DLL dlln/a
Quakbot
2023-04-05 18:52:2583d824ee5b3287b4f42badc78e0dac22DLL dlln/a
Quakbot