Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 154.79.251.172 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:154.79.251.172
Hostname:172-251-79-154.r.airtelkenya.com
AS number:AS36926
AS name:CKL1-ASN
Country:- KE
First seen:2021-04-22 22:04:30 UTC
Last online:2021-05-06 07:xx:xx UTC
Malware:TrickBot

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusLast online (UTC)
2021-04-22 22:04:30154.79.251.172443
TrickBot
Online
2021-05-06 07:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 154.79.251.172. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2021-05-06 00:32:211d677bf5bd133228738a4bef78ea4535Executable exen/a
TrickBot
2021-05-05 15:30:3798b5853fd311b65a78be9f96e8c7374dExecutable exeVirustotal results 41.43%
n/a
2021-05-05 15:23:50e1a32f5cb8b96cc1ca34dba257af22feExecutable exeVirustotal results 44.29%
TrickBot
2021-05-05 13:53:469f7becaa44d2b4c0e65997f7223df457Executable exeVirustotal results 40.00%
TrickBot
2021-05-05 13:50:25fe87a4c23475e905effdd0684ef46a7dExecutable exeVirustotal results 50.72%
TrickBot
2021-05-04 19:10:09fe34675e608a022a2c86cca3def1acbbExecutable exen/a
TrickBot
2021-05-04 17:55:535de02dc8be5f699541e687e2d72b6542Executable exen/a
n/a
2021-05-04 13:12:087d0677090f557c47c259fb718c4a06bdExecutable exen/a
n/a
2021-05-04 13:07:29eb70b6c24c0466954169882dbe5729a4DLL dllVirustotal results 21.74%
TrickBot
2021-04-30 14:19:452a5a0ecf67104b652814ffd0f6a51bb1Executable exeVirustotal results 50.70%
TrickBot
2021-04-29 18:28:250e1675b3b47039d34fd5cf40d4b13de1DLL dllVirustotal results 14.71%
n/a