Browse Botnet C&Cs

You are currently viewing the database entry for the Heodo botnet command&control server (C&C) 105.228.39.7. You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


Host:105.228.39.7
Hostname:105-228-39-7.north.dsl.telkomsa.net
Status:Offline
Spamhaus SBL:Not listed
Malware:Heodo -
AS number:AS37457
AS name:Telkom-Internet
Country:- ZA
First seen:2018-05-09 08:54:31 UTC
Last seen:2019-03-25 22:44:02 UTC

Malware Samples


The table below documents all malware samples associated with this Heodo botnet command&control server (C&C).

Timestamp (UTC)Malware Sample (MD5 hash)VTHostPortSignature
2019-03-27 14:36:059bd88c083a897106fc7a9a0449f22f08Virustotal results 52/68 (76.47%) 105.228.39.780Heodo
2019-02-02 06:13:02a2e82ccce86af4cdde6845a96bd08fdaVirustotal results 51/69 (73.91%) 105.228.39.780Heodo
2019-01-08 20:17:28887a0121fbd6bf069b210ceac55a1bcfVirustotal results 50/67 (74.63%) 105.228.39.780Heodo
2018-11-08 17:32:07a6f08c321a44ed142feb0fc0d8a8fc9bVirustotal results 42/66 (63.64%) 105.228.39.780Heodo

# of malware samples: 4