Browse Botnet C&Cs

You are currently viewing the database entry for the TrickBot botnet command&control server (C&C) 198.46.161.221. You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


Host:198.46.161.221
Hostname:198-46-161-221-host.colocrossing.com
Status:Offline
Spamhaus SBL:Not listed
Malware:TrickBot
AS number:AS36352
AS name:AS-COLOCROSSING - ColoCrossing
Country:- US
First seen:2019-11-17 02:14:24 UTC
Last seen:2019-11-17 19:41:49 UTC
Last online:2019-11-18

Malware Samples


The table below documents all malware samples associated with this TrickBot botnet command&control server (C&C).

Timestamp (UTC)Malware Sample (MD5 hash)VTHostPortSignature
2019-11-18 03:19:434a879b2228bd7437e5ce029f7c618e95Virustotal results 37 / 71 (52.11%) 198.46.161.221447TrickBot
2019-11-18 01:46:18c02796fcac8cd0a3bc56d0ad3bf484e1Virustotal results 38/71 (53.52%) 198.46.161.221447TrickBot
2019-11-17 19:52:187eece05f00f892b169dffb16e79f7931Virustotal results 35/70 (50.00%) 198.46.161.221447TrickBot
2019-11-17 13:51:3455b3d0c8a4c43c076cf812b11e42d260Virustotal results 26 / 70 (37.14%) 198.46.161.221447TrickBot
2019-11-17 12:58:2270fd75cf60cefc828fe52f27a21b7359Virustotal results 38/71 (53.52%) 198.46.161.221447TrickBot
2019-11-17 02:27:3938c21a0ad2a09cac57fe944ad62f9d6eVirustotal results 37/71 (52.11%) 198.46.161.221447TrickBot

# of malware samples: 6