Browse Botnet C&Cs

You are currently viewing the database entry for the TrickBot botnet command&control server (C&C) 192.227.232.21. You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


Host:192.227.232.21
Hostname:192-227-232-21-host.colocrossing.com
Status:Offline
Spamhaus SBL:Not listed
Malware:TrickBot
AS number:AS36352
AS name:AS-COLOCROSSING - ColoCrossing
Country:- US
First seen:2019-12-09 14:12:03 UTC
Last seen:2019-12-11 20:51:37 UTC
Last online:2019-12-19

Malware Samples


The table below documents all malware samples associated with this TrickBot botnet command&control server (C&C).

Timestamp (UTC)Malware Sample (MD5 hash)VTHostPortSignature
2019-12-22 14:01:29aadc0e2cec627c00d56913dfbc48b813Virustotal results 52 / 73 (71.23%) 192.227.232.21443TrickBot
2019-12-12 06:52:48833de351f89e5b44d202d4f742274625Virustotal results 26 / 69 (37.68%) 192.227.232.21443TrickBot
2019-12-11 11:58:06c71048ff9e8a3d4b0cd88e79c5b9014aVirustotal results 30 / 71 (42.25%) 192.227.232.21443TrickBot
2019-12-11 11:58:06c71048ff9e8a3d4b0cd88e79c5b9014aVirustotal results 30 / 71 (42.25%) 192.227.232.21443TrickBot
2019-12-10 07:23:355cdf52755fb22ea1ab1373c1bf681ec9n/a192.227.232.21443TrickBot
2019-12-10 06:43:320d1fc4ab40063ce52706c3c7b4597a32n/a192.227.232.21443TrickBot
2019-12-10 03:48:08331b161ced277092e64770fc98831d21n/a192.227.232.21443TrickBot
2019-12-09 22:43:18524b206170190594067b2a752df60bc3n/a192.227.232.21443TrickBot
2019-12-09 22:43:18524b206170190594067b2a752df60bc3n/a192.227.232.21443TrickBot
2019-12-09 21:01:3088a7201fd2648cc1c22a67e78d092003n/a192.227.232.21443TrickBot
2019-12-09 19:57:22d16c22f947224fc7ea791716eceb112cn/a192.227.232.21443TrickBot
2019-12-09 15:29:45bb31ada1d1c38799c290d3d78d4a9d64n/a192.227.232.21443TrickBot

# of malware samples: 12