Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 46.252.38.244 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:46.252.38.244
Hostname:n/a
AS number:AS21183
AS name:ABCOM-AS Tirana, Albania
Country:- AL
First seen:2021-02-03 04:58:41 UTC
Last online:2021-03-26 13:xx:xx UTC

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusAbuse complaint sent?Last online (UTC)
2021-02-03 04:58:4146.252.38.244447
TrickBot
Offline
No2021-03-26 13:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 46.252.38.244. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2021-02-17 13:37:220ef29511ab45cbd71d5f410a0a1b7722Word file xlsn/a
TrickBot
2021-02-13 22:00:50ae9142ea198475bedd310032398f2be4Executable exeVirustotal results 63.77%
TrickBot
2021-02-13 19:18:30c4a424910afc41423ba75b53bdf13391Executable exeVirustotal results 61.43%
TrickBot
2021-02-13 19:14:386fae87fd37f1ded42a548ced016b392eExecutable exen/a
TrickBot
2021-02-10 19:25:4906a5998092444e0fc940b1a6c33bf7bbWord file xlsn/a
SilentBuilder
2021-02-10 19:13:1662744858481233555661f2619c502129Word file xlsn/a
TrickBot
2021-02-10 19:13:055d34a2b00074553d09a4ecd9581dd860Word file xlsn/a
SilentBuilder
2021-02-10 18:59:475048304e84e6e1f9f259c5731a817d32Word file xlsn/a
SilentBuilder
2021-02-10 15:07:2074783647bf318e528a7fb054479388a6Word file xlsn/a
SilentBuilder
2021-02-10 13:54:15cb42fffd8931932840601e4db0ecc37eExecutable exen/a
n/a
2021-02-10 13:27:13a0e7a1c2df79a80294f0fdf2d3491e3eExecutable exen/a
TrickBot
2021-02-09 02:11:50a8e621589f477a0143c6f5cbc14f8e06Executable exen/a
TrickBot
2021-02-08 20:02:06e5dd9dbba7348e864fceb6a9f1da9bf5Executable exen/a
TrickBot
2021-02-08 16:08:3732b3fa21dfd4235ee097ea381284cddbExecutable exen/a
TrickBot
2021-02-08 15:09:05c8aced544fb0fa4491eecfecdee8cfa6Executable exen/a
TrickBot
2021-02-08 11:04:3386709d3defc785aace06dbbd48f62d58Executable exen/a
TrickBot
2021-02-08 02:38:43231f51032eea92c2de9c0f1fa289b360Executable exen/a
TrickBot
2021-02-08 00:40:35052d73c7e023ecc0405d049ef9f5a1b0Executable exen/a
TrickBot
2021-02-07 21:32:12310d78177a556ee91ee44fdaad828709Executable exen/a
TrickBot
2021-02-07 21:29:523315cd233aa3c29a317225afc08c3920Executable exen/a
TrickBot
2021-02-07 20:20:358b5e6866e67119313a3e230c622a5f0dExecutable exen/a
TrickBot
2021-02-07 20:01:538d460fa4f61083ef9e6ba28362aec0b8Executable exen/a
TrickBot
2021-02-07 17:32:2914ff97c89888dde17ce734a5877535c4Executable exen/a
TrickBot
2021-02-07 16:07:30a36af5bf1b9de24bc59e42696304bd69Executable exen/a
TrickBot
2021-02-07 05:08:518b3e73cd778b1c595c4c4e16e86f8968Executable exen/a
TrickBot
2021-02-07 02:16:46649825a1c01ae2e7be5023a597b64c14Executable exen/a
TrickBot
2021-02-06 13:22:11c19c16eaac661276104f901bda2613f6Executable exen/a
TrickBot
2021-02-06 12:34:01dc24bf1c165507f89ceb46ff51de3953Executable exen/a
TrickBot
2021-02-06 07:49:57d4e84799e9148ab1d5e61ccce01a649eExecutable exen/a
TrickBot
2021-02-05 21:41:0102a8ce3e5dcdb8071a780e0bb13f0951Executable exen/a
TrickBot
2021-02-05 20:35:5247843de93c1d0e93306e5c5fc9901212Executable exen/a
TrickBot
2021-02-04 21:39:5754419b077e2dcf89327f92dedb27d0ffExecutable exen/a
TrickBot
2021-02-04 18:58:381f412ffa8efcc8ff3769f68abd21ce6bExecutable exeVirustotal results 52.86%
TrickBot
2021-02-04 16:27:55acbcd4d317958d318b28dd3acad2d8cbWord file xlsn/a
TrickBot
2021-02-04 16:25:3601fcde263413443df746f04427d16476Word file xlsn/a
TrickBot
2021-02-04 14:38:33be40ff21ef6113426de8338bbabfdc10Word file xlsn/a
TrickBot
2021-02-03 13:50:131f21803a1ab4f2d4f1eb82c7c30abca5Executable exen/a
TrickBot
2021-02-03 04:28:371b9372c95f92e5a8880bcf15d8aaed42Executable exen/a
TrickBot
2021-02-03 03:33:59c4fb221710157ef9bcc8a27fff0c569cExecutable exen/a
n/a