Browse Botnet C&Cs

You are currently viewing the database entry for the TrickBot botnet command&control server (C&C) 212.109.223.12. You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


Host:212.109.223.12
Hostname:derin.m
Status:Offline
Spamhaus SBL:SBL448298
Malware:TrickBot
AS number:AS29182
AS name:THEFIRST-AS
Country:- RU
First seen:2019-07-14 02:00:52 UTC
Last seen:2019-07-22 01:25:13 UTC
Last online:2019-07-25

Malware Samples


The table below documents all malware samples associated with this TrickBot botnet command&control server (C&C).

Timestamp (UTC)Malware Sample (MD5 hash)VTHostPortSignature
2019-07-24 08:56:555533bb2e93cd74cfabe8c2cdd83cee48Virustotal results 27/65 (41.54%) 212.109.223.12447TrickBot
2019-07-24 00:16:177cf6831a30712b001b51d9ed3b7a0c3bVirustotal results 36/71 (50.70%) 212.109.223.12447TrickBot
2019-07-24 00:16:177cf6831a30712b001b51d9ed3b7a0c3bVirustotal results 36/71 (50.70%) 212.109.223.12447TrickBot
2019-07-22 21:54:32a69c7692b496dbc544ed442e75e7a452Virustotal results 27/71 (38.03%) 212.109.223.12447TrickBot

# of malware samples: 4