Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 204.138.26.220 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:204.138.26.220
Hostname:n/a
AS number:AS209
AS name:CENTURYLINK-US-LEGACY-QWEST
Country:- US
First seen:2021-07-04 07:15:42 UTC
Last online:2021-07-23 06:xx:xx UTC

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusAbuse compltain sent?Last online (UTC)
2021-07-04 07:15:42204.138.26.220443
TrickBot
Offline
No2021-07-23 06:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 204.138.26.220. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2021-07-24 06:02:292460a4cb23dd8666a4e91719d5dd6bd4Executable exen/a
TrickBot
2021-07-22 14:50:45336ba3b83d14975fa9c7fb77e47f991bDLL dllVirustotal results 47.83%
TrickBot
2021-07-20 19:44:48f14377c4a8b88c4b57c6a307cf8a871aDLL dlln/a
n/a
2021-07-20 19:14:19b414e5a7e9faac4eb58b66bd0e6d9a78DLL dlln/a
TrickBot
2021-07-20 16:00:130cc96c7dfa43daa71f5b217950caeabbDLL dlln/a
TrickBot
2021-07-20 15:55:199d3883fbd7070b814c734ae913457bcbjsn/a
n/a
2021-07-20 15:41:42b49309d4b4054ae093dff9837207edc3DLL dlln/a
TrickBot
2021-07-16 20:32:35452b85a212ae64a58f7db3bdc8013bd0DLL dllVirustotal results 54.41%
TrickBot
2021-07-06 04:15:499177f9765f7ae10904f97e9e9053ab19DLL dlln/a
TrickBot
2021-07-05 23:13:2571a6d2f09d0f156d18f9ee0c2bd3f39bDLL dlln/a
n/a
2021-07-04 06:18:40aad8f77161e900395f1e144c2726bdceDLL dllVirustotal results 26.47%
TrickBot