Browse Botnet C&Cs

You are currently viewing the database entry for the TrickBot botnet command&control server (C&C) 192.3.253.217. You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


Host:192.3.253.217
Hostname:192-3-253-217-host.colocrossing.com
Status:Offline
Spamhaus SBL:SBL457275
Malware:TrickBot
AS number:AS36352
AS name:AS-COLOCROSSING - ColoCrossing
Country:- US
First seen:2019-08-08 19:15:54 UTC
Last seen:2019-08-08 19:15:54 UTC
Last online:2019-08-15

Malware Samples


The table below documents all malware samples associated with this TrickBot botnet command&control server (C&C).

Timestamp (UTC)Malware Sample (MD5 hash)VTHostPortSignature
2019-08-20 14:22:482305fc9e60c6a00c4781fb6da59e7e2fVirustotal results 32 / 68 (47.06%) 192.3.253.217443TrickBot
2019-08-19 15:12:16505a6528904480e0db4baf40821433edVirustotal results 43/69 (62.32%) 192.3.253.217443TrickBot
2019-08-17 11:56:56ae3f92105d72144e869d0b5afadc884cVirustotal results 44/69 (63.77%) 192.3.253.217443TrickBot
2019-08-17 08:29:57619f223b804c45928e6beddee0163f60Virustotal results 53/68 (77.94%) 192.3.253.217443TrickBot
2019-08-16 19:34:40adb505ea1442b9806f3f6ac7c13171edVirustotal results 45/71 (63.38%) 192.3.253.217443TrickBot
2019-08-16 19:34:40adb505ea1442b9806f3f6ac7c13171edVirustotal results 45/71 (63.38%) 192.3.253.217443TrickBot
2019-08-16 08:51:070692637bfc4fc60b2417b7f6ebe6fe9bVirustotal results 45/69 (65.22%) 192.3.253.217443TrickBot
2019-08-16 06:46:36c15fcb0d32c1284d5f11fb76b7a125a9Virustotal results 17/66 (25.76%) 192.3.253.217443TrickBot
2019-08-16 06:41:476e4212e9e12def0922dbbe22bf5a4d6fVirustotal results 46/70 (65.71%) 192.3.253.217443TrickBot
2019-08-14 13:48:23abc6af59755275160228cea480de8ec3Virustotal results 37 / 71 (52.11%) 192.3.253.217443TrickBot
2019-08-14 13:48:23abc6af59755275160228cea480de8ec3Virustotal results 37 / 71 (52.11%) 192.3.253.217443TrickBot

# of malware samples: 11