Browse Botnet C&Cs

You are currently viewing the database entry for the TrickBot botnet command&control server (C&C) 185.99.2.167. You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


Host:185.99.2.167
Hostname:scream.cyberlike.org
Status:Offline
Spamhaus SBL:Not listed
Malware:TrickBot
AS number:AS200698
AS name:GLOBALHOST-BOSNIA-AS
Country:- BA
First seen:2019-11-16 15:15:22 UTC
Last seen:2019-11-17 19:41:49 UTC
Last online:2019-11-18

Malware Samples


The table below documents all malware samples associated with this TrickBot botnet command&control server (C&C).

Timestamp (UTC)Malware Sample (MD5 hash)VTHostPortSignature
2019-11-17 19:52:187eece05f00f892b169dffb16e79f7931Virustotal results 35/70 (50.00%) 185.99.2.167447TrickBot
2019-11-17 19:50:241709a969a8500e56982e71303065c8d0Virustotal results 37/71 (52.11%) 185.99.2.167447TrickBot
2019-11-17 15:16:557058324993b4bd2b30bbb97d68eb43c7Virustotal results 26 / 71 (36.62%) 185.99.2.167447TrickBot
2019-11-17 14:58:40893e14030786a7ae0543a4b1ee747ea4Virustotal results 25 / 69 (36.23%) 185.99.2.167447TrickBot
2019-11-17 14:23:252324b37dc582be2872721036e6c17470Virustotal results 36/67 (53.73%) 185.99.2.167447TrickBot
2019-11-17 13:45:31ed77557cc5f1e33dba3087604f379f7cVirustotal results 26 / 70 (37.14%) 185.99.2.167447TrickBot
2019-11-17 13:45:31ed77557cc5f1e33dba3087604f379f7cVirustotal results 26 / 70 (37.14%) 185.99.2.167447TrickBot
2019-11-17 13:31:31c0612d4d04eded5a6bde6084747a3f74Virustotal results 26 / 69 (37.68%) 185.99.2.167447TrickBot
2019-11-17 13:17:16052521705c1b1f95077f9f0bf2dcc2ccVirustotal results 26 / 70 (37.14%) 185.99.2.167447TrickBot
2019-11-17 02:26:43188cde8560b479b6ef729b7ee896282fVirustotal results 38/69 (55.07%) 185.99.2.167447TrickBot
2019-11-16 15:26:2761080843b2192d55f3bb13e0e08befa8Virustotal results 30/69 (43.48%) 185.99.2.167447TrickBot

# of malware samples: 11