Browse Botnet C&Cs

You are currently viewing the database entry for the Heodo botnet command&control server (C&C) 72.52.216.110. You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


Host:72.52.216.110
Hostname:host.thenationalrealestatepost.com
Status:Offline
Spamhaus SBL:Not listed
Malware:Heodo -
AS number:AS32244
AS name:LIQUIDWEB - Liquid Web, L.L.C
Country:- US
First seen:2018-05-30 03:07:12 UTC
Last seen:2019-02-01 06:35:20 UTC

Malware Samples


The table below documents all malware samples associated with this Heodo botnet command&control server (C&C).

Timestamp (UTC)Malware Sample (MD5 hash)VTHostPortSignature
2019-02-02 06:13:02a2e82ccce86af4cdde6845a96bd08fdaVirustotal results 51/69 (73.91%) 72.52.216.1108080Heodo
2019-01-08 19:50:1562e8dbd56c687be4e960a2f4b019cdabVirustotal results 54/68 (79.41%) 72.52.216.1108080Heodo
2019-01-08 14:43:1432dd6ca1cb3c3d363932bac8fd0e447bVirustotal results 51/69 (73.91%) 72.52.216.1108080
2019-01-08 09:23:59db0a60f9ea1999c59aa2dcd2ac49e38eVirustotal results 46/62 (74.19%) 72.52.216.1108080
2018-12-24 07:49:51024516b7611909efbcc588bf5066b295Virustotal results 48/67 (71.64%) 72.52.216.1108080Heodo
2018-12-23 09:14:3545cde5c06adcc8e047a0dd4c2eabcebbVirustotal results 52/67 (77.61%) 72.52.216.1108080Heodo

# of malware samples: 6