Browse Botnet C&Cs

You are currently viewing the database entry for the Heodo botnet command&control server (C&C) 158.58.170.24. You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


Host:158.58.170.24
Hostname:foosoft.it
Status:Offline
Spamhaus SBL:Not listed
Malware:Heodo -
AS number:AS49367
AS name:ASSEFLOW Amsterdam Internet Exchange (AMS-IX)
Country:- IT
First seen:2018-03-16 16:16:51 UTC
Last seen:2019-01-08 09:21:28 UTC

Malware Samples


The table below documents all malware samples associated with this Heodo botnet command&control server (C&C).

Timestamp (UTC)Malware Sample (MD5 hash)VTHostPortSignature
2019-01-08 21:01:35ce9d928c96b106a7ad44c9e579d3f443Virustotal results 56/68 (82.35%) 158.58.170.244143Heodo
2019-01-08 13:50:594f2e3205042e801c90a78546c57452e2Virustotal results 47/67 (70.15%) 158.58.170.244143Heodo
2019-01-08 08:05:116603a61200564f7f1b7f39376927ac12Virustotal results 56/68 (82.35%) 158.58.170.244143Heodo

# of malware samples: 3