Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 91.35.212.133 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:91.35.212.133
Hostname:p5b23d485.dip0.t-ipconnect.de
AS number:AS3320
AS name:DTAG Internet service provider operations
Country:- DE
First seen:2023-04-20 16:35:08 UTC
Last online:2023-04-25 07:xx:xx UTC

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusAbuse complaint sent?Last online (UTC)
2023-04-20 16:35:0891.35.212.133995
QakBot
Offline
Yes (2023-04-20 16:40:09 UTC)2023-04-25 07:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 91.35.212.133. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2023-04-28 22:17:0494020c05016530f67346f264decbd09eDLL dllVirustotal results 45.71%
Quakbot
2023-04-28 02:17:551dd4c7b982456298ae83a98f43de1564DLL dllVirustotal results 51.43%
Quakbot
2023-04-25 15:50:59c0371da158334450b88f696d2ac4a95dDLL dlln/a
Quakbot
2023-04-24 17:59:3384245e4d3f37eca7de384987b01e5d55DLL dlln/a
Quakbot
2023-04-23 19:07:095c2dd16a3e14b011b01007086df3a5daDLL dllVirustotal results 42.86%
Quakbot
2023-04-22 05:02:536cf288f617eccd20bb65972a5e831b9fDLL dllVirustotal results 32.84%
Quakbot
2023-04-21 17:34:52ee5968f3f032a01183b8a9eec0dda50cDLL dllVirustotal results 25.71%
Quakbot
2023-04-21 07:35:56891af6869537682b57c480c3af0eb594DLL dllVirustotal results 8.57%
Quakbot
2023-04-20 16:28:3245f241fd144ec617a7610cb4edc51f30DLL dllVirustotal results 21.31%
n/a