Browse Botnet C&Cs

You are currently viewing the database entry for the TrickBot botnet command&control server (C&C) 185.99.2.127. You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


Host:185.99.2.127
Hostname:bagux.we.bs
Status:- Online
Spamhaus SBL:Not listed
Malware:TrickBot
AS number:AS200698
AS name:GLOBALHOST-BOSNIA-AS
Country:- BA
First seen:2020-04-29 21:39:21 UTC
Last seen:2020-05-13 17:19:08 UTC
Last online:2020-05-25

Malware Samples


The table below documents all malware samples associated with this TrickBot botnet command&control server (C&C).

Timestamp (UTC)Malware Sample (MD5 hash)VTHostPortSignature
2020-05-14 21:34:1042f81bf5dbe19308096c869803b05141n/a185.99.2.127447TrickBot
2020-05-10 08:20:2733424aea3f19f05cb9723b4d6b5b2294Virustotal results 52 / 73 (71.23%) 185.99.2.127447TrickBot
2020-05-09 09:46:04f1f1c16863e79e0bf0be44ecca8e3f66Virustotal results 41 / 71 (57.75%) 185.99.2.127447TrickBot

# of malware samples: 3