Malware Signature

The following table shows a list of malware samples and the corresponding botnet C&C (ip:port) associated with Spambot.Kelihos

Database Entry


Malware:Spambot.Kelihos
First seen:2014-04-27 14:08:58 UTC
Last seen:2019-05-19 08:41:52 UTC

Malware Samples


The table below documents all malware samples associated with this malware family.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2019-02-26 09:52:534f2607faec3cb30dc8c476c7029f9046Virustotal results 21/66 (31.82%) Spambot.Kelihos3.121.182.157:1604
2016-08-27 16:10:347be9383e8157823f6f26d59c8fe9313cVirustotal results 39/58 (67.24%) Spambot.Kelihos23.234.26.210:5658
2016-08-26 16:33:39e2e1be94fbfa7586db3dd9bfa15dc877Virustotal results 40/57 (70.18%) Spambot.Kelihos23.234.26.210:5658
2016-08-19 22:52:23a423eaf7648d5f5f998f57f76a36b6fcVirustotal results 35/43 (81.40%) Spambot.Kelihos64.111.42.64:443
2016-08-10 16:22:404e68281eb66af9c433d9a247367e09e7Virustotal results 35/55 (63.64%) Spambot.Kelihos23.234.26.210:5658
2016-08-08 21:30:58e8d30411a54b702bb213bb11312ba5bfVirustotal results 44/55 (80.00%) Spambot.Kelihos62.22.91.92:443
2016-08-04 22:18:02cdcff0e4486946b36a07f023cbd11241n/aSpambot.Kelihos204.95.99.204:443
2016-08-04 20:55:306d3073cf7ef553a9a69016dff8c11ba7Virustotal results 25/55 (45.45%) Spambot.Kelihos23.234.26.210:5658
2016-08-04 09:41:42071a1a716d0fb8b42cfcf56fdae94bccVirustotal results 21/54 (38.89%) Spambot.Kelihos23.234.26.210:5658
2016-08-02 16:34:2235f1e48875870aab36581bf9b52ff070Virustotal results 31/55 (56.36%) Spambot.Kelihos23.234.26.210:5658
2016-08-02 15:05:457e285ca2395f61dc82d20c344a71c461Virustotal results 35/64 (54.69%) Spambot.Kelihos23.234.26.210:5658
2016-08-01 10:27:59510d65ec726ee10d171994b18e68be4fVirustotal results 37/55 (67.27%) Spambot.Kelihos23.234.26.210:5658
2016-08-01 10:27:0984cb4dc8670979e298ef050273a52c50Virustotal results 3/55 (5.45%) Spambot.Kelihos23.234.26.210:5658
2016-08-01 06:37:36ca12b988b931a09b04735399b85bcacaVirustotal results 1/55 (1.82%) Spambot.Kelihos23.234.26.210:5658
2016-07-27 19:52:44c213433991fe828b64fa9a2995d3e995Virustotal results 20/55 (36.36%) Spambot.Kelihos23.234.26.210:5658
2016-07-26 17:16:1683ba944c9c8fce91daa68d1b2cc3cba6Virustotal results 14/55 (25.45%) Spambot.Kelihos23.234.26.210:5658
2016-07-25 13:38:29215436ebe6d7ca58cf3e15fc1cb7b501Virustotal results 13/54 (24.07%) Spambot.Kelihos23.234.26.210:5658
2016-07-24 11:15:43dc0bd2cbe69e010d0a4d5ebdff9f8dc1Virustotal results 24/53 (45.28%) Spambot.Kelihos23.234.26.210:5658
2016-07-24 09:35:49f4d7ecff220b271523ae7b2981c02dfcVirustotal results 36/66 (54.55%) Spambot.Kelihos23.234.26.210:5658
2016-07-23 06:57:05556b562da055cbbae2a76fb3643afe1bVirustotal results 8/55 (14.55%) Spambot.Kelihos23.234.26.210:5658
2016-07-22 17:27:30f03358283de74afb4c123c350c78e88bn/aSpambot.Kelihos23.234.26.210:5658
2016-07-22 05:03:282ee9b66854485a6df647c444dbb11d73Virustotal results 1/55 (1.82%) Spambot.Kelihos23.234.26.210:5658
2016-07-21 11:22:2309a4e85b60d9be56cfe4dcd940158f71Virustotal results 34/54 (62.96%) Spambot.Kelihos23.234.26.210:5658
2016-07-21 08:39:44e4826533a45aa9b896c5a5c14bacc779Virustotal results 33/54 (61.11%) Spambot.Kelihos23.234.26.210:5658
2015-07-10 11:53:1029e93f6d8c88ff8175a71d738e3231b7Virustotal results 8/56 (14.29%) Spambot.Kelihos78.47.143.212:443