Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 81.159.211.209 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:81.159.211.209
Hostname:host81-159-211-209.range81-159.btcentralplus.com
AS number:AS2856
AS name:BT-UK-AS BTnet UK Regional network
Country:- GB
First seen:2023-04-26 14:01:10 UTC
Last online:2023-05-01 17:xx:xx UTC

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusAbuse complaint sent?Last online (UTC)
2023-04-26 14:01:1081.159.211.2092222
QakBot
Offline
Yes (2023-04-26 14:05:04 UTC)2023-05-01 17:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 81.159.211.209. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2023-05-03 21:53:31449cf22ebe078a8fe4874043fae803b0DLL dllVirustotal results 47.14%
Quakbot
2023-05-03 21:38:120977be397cf3c4f8463827564ccfd7fcDLL dllVirustotal results 49.28%
Quakbot
2023-05-03 20:56:14923d9f6c3eb523de5050f303eaf6b975DLL dllVirustotal results 46.38%
Quakbot
2023-04-29 23:14:29545950802cb05c1630fde3a6b417a99dDLL dlln/a
Quakbot
2023-04-29 09:40:076c8e152b87362c00ca1cdb49e8bcc6d5DLL dlln/a
Quakbot
2023-04-28 22:18:22dccf2eba3aa22dcef646885bc26c5208DLL dlln/a
Quakbot
2023-04-27 19:09:376924f56e801db0a071ddb0bde3785fc9DLL dllVirustotal results 31.43%
Quakbot
2023-04-27 08:42:493676c55ee07e96f591d36086252b11b0DLL dllVirustotal results 18.57%
Quakbot