Browse Botnet C&Cs

You are currently viewing the database entry for the Heodo botnet command&control server (C&C) 66.191.63.170. You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


Host:66.191.63.170
Hostname:66-191-63-170.static.stpt.wi.charter.com
Status:Offline
Spamhaus SBL:Not listed
Malware:Heodo -
AS number:AS20115
AS name:,
Country:- US
First seen:2018-08-28 10:16:57 UTC
Last seen:2019-01-08 08:20:33 UTC

Malware Samples


The table below documents all malware samples associated with this Heodo botnet command&control server (C&C).

Timestamp (UTC)Malware Sample (MD5 hash)VTHostPortSignature
2019-01-08 22:32:2806cc232f9a61e4ee82ebf62ff3349d24Virustotal results 47/69 (68.12%) 66.191.63.1708080
2019-01-08 21:39:452f5d457159e9a64e9cd81777cfbab943Virustotal results 49/68 (72.06%) 66.191.63.1708080Heodo
2013-11-28 19:26:153dccb6aa321f455e5e1e1bc5b40aea39n/a66.191.63.1708080Downloader.Upatre
2013-11-28 17:18:54c7986a6341c10507b929cd3416f24b5en/a66.191.63.1708080Downloader.Upatre
2012-10-25 18:01:22f61874d7af7303686d4159f792527eb2Virustotal results 28/44 (63.64%) 66.191.63.1708080ZeuS

# of malware samples: 5