Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 87.221.197.91 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:87.221.197.91
Hostname:91.197.221.87.dynamic.jazztel.es
AS number:AS12479
AS name:UNI2-AS
Country:- ES
First seen:2023-04-20 18:51:28 UTC
Last online:2023-04-20 20:xx:xx UTC

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusAbuse complaint sent?Last online (UTC)
2023-04-20 18:51:2887.221.197.912222
QakBot
Offline
Yes (2023-04-20 18:55:03 UTC)2023-04-20 20:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 87.221.197.91. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2023-04-29 13:38:507e337b76cbec769f82ea3b4f0b0dadb9DLL dlln/a
Quakbot
2023-04-27 05:33:28e3149f0478d2d5feefd6a95b6088bdc5DLL dllVirustotal results 48.57%
Quakbot
2023-04-27 05:25:4463adcd4e4f405e7ecce6f3ffdc77d8b2DLL dllVirustotal results 47.14%
Quakbot
2023-04-26 04:58:229b67a4ae5c96247af63a61a4e7c41717DLL dllVirustotal results 45.71%
Quakbot
2023-04-23 19:06:5634164c1b949f1f5da00b33063e3979d6DLL dllVirustotal results 42.86%
Quakbot
2023-04-23 00:00:22531060d290cf9c711bb3777d9e805ca1DLL dlln/a
Quakbot
2023-04-22 05:04:337f7a47c51c4773e8faaa9c3155247e1dDLL dllVirustotal results 30.00%
Quakbot
2023-04-22 05:01:3674e604b9ed58b266b5e15097fd88edfcDLL dllVirustotal results 30.16%
Quakbot
2023-04-22 04:59:238ffee077e95d8f17c00ae5b287c011d3DLL dllVirustotal results 32.84%
Quakbot
2023-04-21 09:33:30bfeb67f7c92eccdfb59e150e310bde00DLL dlln/a
Quakbot