Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 185.109.54.99 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:185.109.54.99
Hostname:n/a
AS number:AS199995
AS name:OT-AS
Country:- UA
First seen:2021-01-18 09:17:54 UTC
Last online:2021-02-25 07:xx:xx UTC

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusAbuse complaint sent?Last online (UTC)
2021-01-18 09:17:54185.109.54.99447
TrickBot
Offline
No2021-02-25 07:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 185.109.54.99. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2021-02-19 15:11:178291cbc6873e8019b6c0cb4472393d0fDLL dlln/a
TrickBot
2021-02-13 19:18:201079816b05c6129407f02bf146384f47Executable exeVirustotal results 62.32%
TrickBot
2021-02-12 23:46:195b8c473c794a9c66da63023c1822e5f5Executable exen/a
TrickBot
2021-02-12 23:35:3397c826602f2d2be241b882175e60aebeExecutable exen/a
TrickBot
2021-02-12 23:25:4650a440bc0788f6f039a1d8655871ebe5Executable exen/a
TrickBot
2021-02-12 22:59:184cce85023f81306b04e52098826f5959Executable exen/a
TrickBot
2021-02-12 22:54:33644c5f28587de5b8a6b48c3c6af7ff05Executable exen/a
TrickBot
2021-02-10 10:55:14d564753c69c611fb485af9b66b967630DLL dlln/a
TrickBot
2021-01-27 21:35:145a112434ce7bca2cc540c3f8e0f49d60Executable exeVirustotal results 70.42%
TrickBot
2021-01-27 21:16:21966e9251e168976dac62ae788bd6ae66Executable exeVirustotal results 50.72%
TrickBot
2021-01-07 19:28:27189f3a7c35209b5f37e11498f0154da4Executable exeVirustotal results 54.93%
TrickBot
2021-01-07 19:07:117ec570e990d814053824ccddc259e590Executable exen/a
TrickBot
2021-01-07 17:15:2993daaf13d14b6350b770701acabd7729Executable exen/a
TrickBot
2021-01-06 14:11:5900ed3e85be8ed63fac0a7708ec8f7dd7Executable exen/a
TrickBot
2021-01-06 13:36:41af856d95b168f58149b6a86293de508fExecutable exen/a
TrickBot
2021-01-06 12:04:100085f351a405012bb68c8ee0db08b766Executable exen/a
TrickBot
2021-01-06 09:24:175ec8e034d00af8fc01136abebe70523dExecutable exen/a
TrickBot
2021-01-06 08:15:5799295060194eaa5cc0c5c4762af5993dExecutable exen/a
TrickBot
2021-01-06 07:47:39dad0cf109e853492d7dde2afab546d35Executable exen/a
TrickBot
2021-01-06 07:14:34e2077a57f50bf89dc9e312831a5f7f56Executable exen/a
TrickBot
2021-01-06 06:41:279f3953230afbe86c3ec0a83a512c57feExecutable exen/a
TrickBot
2021-01-06 02:52:134c62adc769707905383006e8e9fb78edExecutable exen/a
TrickBot
2021-01-06 02:36:5021f861a2a7dc0619405cb2a4c10e05b6Executable exen/a
TrickBot
2021-01-06 02:10:084e2eeb8632d2d094628fc9c929489353Executable exen/a
TrickBot
2021-01-06 01:24:26e147ec83cb7f0ee6abb730035266182bExecutable exen/a
TrickBot
2021-01-06 00:49:38030c6c41b07d8312da752d57edf491b0Executable exen/a
TrickBot
2021-01-06 00:12:12e29594838467895c3061e25e564bdda8Executable exen/a
TrickBot
2021-01-04 20:25:51569fa61a870909e2997298b85e70a1d6Executable exeVirustotal results 44.12%
TrickBot
2020-12-31 04:54:07f323781072d10cb1bc1acd6b8c761c55Executable exen/a
TrickBot
2020-12-31 04:36:34e40aa56761225ecdb7a80b79cf01f7fdExecutable exen/a
TrickBot
2020-12-31 04:24:358f6e46570a7b12400d05f83a28ed3fe1Executable exen/a
TrickBot
2020-12-31 03:43:4123575327a4cf80f42fd5041c19f12cf3Executable exen/a
TrickBot