Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 85.6.232.221 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:85.6.232.221
Hostname:221.232.6.85.dynamic.wline.res.cust.swisscom.ch
AS number:AS3303
AS name:SWISSCOM Swisscom Switzerland Ltd
Country:- CH
First seen:2022-07-14 09:30:35 UTC
Last online:2022-07-15 09:xx:xx UTC

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusAbuse complaint sent?Last online (UTC)
2022-07-14 09:30:3585.6.232.2212222
QakBot
Offline
Yes (2022-07-14 09:35:04 UTC)2022-07-15 09:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 85.6.232.221. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2022-07-21 16:33:08c03de59890bb60e2157efdfa0ffdcf2eDLL dlln/a
n/a
2022-07-15 23:37:492fce945f0621e3812618f55c4a3926e9DLL dllVirustotal results 64.71%
n/a
2022-07-15 23:34:58926382093a313282f4a1639944f3fb0cDLL dllVirustotal results 60.87%
n/a
2022-07-15 14:26:3296eb0292ad176c905613678a3125cca5DLL dlln/a
Quakbot
2022-07-14 21:44:5990c7b8f66c18c1e7b06ebd9c8a7f731dDLL dlln/a
n/a
2022-07-14 21:44:29a8c071f4d69627f581fa15495218bff7DLL dlln/a
n/a
2022-07-14 18:34:311fffb3fdb0a4b780385cc5963fd4d40cDLL dlln/a
n/a
2022-07-13 23:34:11a0d132cdc67c29abf79ecf455c4a4e25msiVirustotal results 14.75%
Quakbot
2022-07-12 18:08:5847847ac5f01e037c1a18becc0dfd4611msiVirustotal results 18.33%
Quakbot