Browse Botnet C&Cs

You are currently viewing the database entry for the Heodo botnet command&control server (C&C) 104.15.149.209. You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


Host:104.15.149.209
Hostname:104-15-149-209.lightspeed.irvnca.sbcglobal.net
Status:Offline
Spamhaus SBL:Not listed
Malware:Heodo -
AS number:AS7018
AS name:ATT-INTERNET4 - AT&T Services, Inc., US
Country:- US
First seen:2018-11-08 16:01:33 UTC
Last seen:2018-11-08 16:01:42 UTC

Malware Samples


The table below documents all malware samples associated with this Heodo botnet command&control server (C&C).

Timestamp (UTC)Malware Sample (MD5 hash)VTHostPortSignature
2018-11-11 13:17:159c13143daec8b7beb372be850b96e2ffVirustotal results 40/67 (59.70%) 104.15.149.2098080Heodo
2018-11-09 11:38:5033b4dfaa24419ecf7aacf50c6a3d488eVirustotal results 15/66 (22.73%) 104.15.149.2098080Heodo
2018-11-09 01:12:140020351cc4c2a3ea6e0b1fc5fa684fe3Virustotal results 13/66 (19.70%) 104.15.149.2098080Heodo
2018-11-08 17:12:361bda6f0fffb4523c68317be7eac9d5e0Virustotal results 13/66 (19.70%) 104.15.149.2098080Heodo
2018-11-08 16:01:4282f7a4bb3c787d75ef9e848436c41792Virustotal results 16/66 (24.24%) 104.15.149.2098080Heodo
2018-11-08 14:05:285f4703344714b9b86e22d535a423818eVirustotal results 17/66 (25.76%) 104.15.149.2098080Heodo

# of malware samples: 6