Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 154.79.244.182 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:154.79.244.182
Hostname:182-244-79-154.r.airtelkenya.com
AS number:AS36926
AS name:CKL1-ASN
Country:- KE
First seen:2021-04-22 18:33:10 UTC
Last online:2021-05-06 06:xx:xx UTC
Malware:TrickBot

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusLast online (UTC)
2021-04-22 18:33:10154.79.244.182443
TrickBot
Online
2021-05-06 06:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 154.79.244.182. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2021-05-06 04:31:144e8bfa8b70bac13ec29bbc98324ba3fdExecutable exen/a
n/a
2021-05-05 23:42:2070406711e07b1e49eeac290381e468f2Executable exen/a
TrickBot
2021-05-05 12:53:4043bb4560a4828d3e1dec4b74e16eb460Executable exeVirustotal results 32.86%
TrickBot
2021-05-05 10:11:17a31bfef2703d13950bd8ccb161524729Executable exen/a
TrickBot
2021-05-04 14:05:5809400340aff4826bc684599eb71ffa55Executable exen/a
n/a
2021-05-04 13:11:54d91fc2dec5eaed357f1ab0595b640dc8Executable exen/a
TrickBot
2021-04-29 04:51:0220b6cd409de45d2bf63883a9a7efdf73DLL dllVirustotal results 11.76%
TrickBot
2021-04-22 17:53:01ac2b2336004ae55d79e225ae4634b9caDLL dllVirustotal results 11.76%
TrickBot