Browse Botnet C&Cs

You are currently viewing the database entry for the TrickBot botnet command&control server (C&C) 172.245.159.121. You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


Host:172.245.159.121
Hostname:172-245-159-121-host.colocrossing.com
Status:Offline
Spamhaus SBL:Not listed
Malware:TrickBot
AS number:AS36352
AS name:AS-COLOCROSSING - ColoCrossing
Country:- US
First seen:2019-11-28 19:16:25 UTC
Last seen:2019-12-01 03:56:32 UTC
Last online:2019-12-02

Malware Samples


The table below documents all malware samples associated with this TrickBot botnet command&control server (C&C).

Timestamp (UTC)Malware Sample (MD5 hash)VTHostPortSignature
2019-12-02 07:19:5879e1c9f8ef382549bda842a230f907b0Virustotal results 45/70 (64.29%) 172.245.159.121443TrickBot
2019-12-01 08:59:00cab9e30cef14553368e5dca35f1ef539Virustotal results 57/72 (79.17%) 172.245.159.121443TrickBot
2019-12-01 07:48:141c94e4530965e56c15ce3d0742cb15f9Virustotal results 45/69 (65.22%) 172.245.159.121443TrickBot
2019-12-01 07:48:141c94e4530965e56c15ce3d0742cb15f9Virustotal results 45/69 (65.22%) 172.245.159.121443TrickBot
2019-12-01 07:48:141c94e4530965e56c15ce3d0742cb15f9Virustotal results 45/69 (65.22%) 172.245.159.121443TrickBot
2019-11-30 02:25:373a16ce67dada501ba4f6b4b497f2832cVirustotal results 12 / 70 (17.14%) 172.245.159.121443Heodo
2019-11-28 21:35:56dfd32bacc039b5f498921e1041091902Virustotal results 47/69 (68.12%) 172.245.159.121443TrickBot
2019-11-28 21:35:56dfd32bacc039b5f498921e1041091902Virustotal results 47/69 (68.12%) 172.245.159.121443TrickBot
2019-11-28 21:35:56dfd32bacc039b5f498921e1041091902Virustotal results 47/69 (68.12%) 172.245.159.121443TrickBot
2019-11-28 19:28:424d66f93aa5d0b16462d8cb8f0e608160Virustotal results 46/70 (65.71%) 172.245.159.121443TrickBot

# of malware samples: 10