Malware Botnet C&C

You are currently viewing the database entry for the malware botnet command&control server (C&C) hosted at 5.2.158.159 . You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


IP address:5.2.158.159
Hostname:static-5-2-158-159.rdsnet.ro
AS number:AS8708
AS name:RCS-RDS 73-75 Dr. Staicovici
Country:- RO
First seen:2021-03-24 01:46:46 UTC
Last online:2021-03-26 15:xx:xx UTC
Malware:TrickBot

Botnet C&Cs

The table below shows all botnet C&Cs know to Feodo Tracker that are hosted on this host.

First seen (UTC)IP addressPortMalwareStatusLast online (UTC)
2021-03-24 01:46:465.2.158.159447
TrickBot
Offline
2021-03-26 15:xx:xx

Referencing Malware Samples

The following table shows the most recent malware samples associated with malware botnet C&Cs hosted on 5.2.158.159. Please consider that the output is limited to the 500 most recent malware samples.

Time stamp (UTC)MD5 hashFile TypeVirustotalMalware
2021-03-25 01:13:17c46c0c1ef28a643491a7713c03a67e9bWord file xlsmn/a
TrickBot
2021-03-25 01:08:5341a227bb39485186fed3e4b0e4aa2ad8Word file xlsmn/a
TrickBot
2021-03-25 00:42:50c6ae1ae788490b2b07b1e268f1730067Word file xlsmn/a
TrickBot
2021-03-25 00:33:18115a7612c7bffe3769d16a2606e45e8cWord file xlsmn/a
TrickBot
2021-03-25 00:26:429bff2f0a75a218b505e3fb3e38aea06dWord file xlsmn/a
TrickBot
2021-03-25 00:12:449eeee4195fe44683767c45bd8ef7f00eWord file xlsmn/a
TrickBot
2021-03-25 00:06:43508e1402674970201aa80f3aa7158775Word file xlsmn/a
TrickBot
2021-03-25 00:05:57013c6dab360baa53bd3c597ca8e63a26Word file xlsmn/a
TrickBot
2021-03-24 23:58:480f758182b8643bd890d6d803ee339659Word file xlsmn/a
TrickBot
2021-03-24 23:55:49a9299ef226cae8cbb393d0cb8b40ce19Word file xlsmn/a
TrickBot
2021-03-24 23:55:343d785e622304a4828d479020b3aa93baWord file xlsmn/a
TrickBot
2021-03-24 23:54:037698ba7c16852647716bb1628b9f27c1Word file xlsmn/a
TrickBot
2021-03-24 23:53:1993f085c5f0c3bd5821a1521cef6a5de7Word file xlsmn/a
TrickBot
2021-03-24 23:48:34fb3168dfd970f7925f8a4710c2bb940dWord file xlsmn/a
TrickBot
2021-03-24 23:45:57917c22c456d1de7c211e46a86532e3c9Word file xlsmn/a
TrickBot
2021-03-24 23:44:147ca9adf47f43b0cc525c2bd9d74a1282Word file xlsmn/a
TrickBot
2021-03-24 08:33:42a566a0a4a1be8105f06f87ef0ebb7b63Executable exen/a
n/a
2021-03-24 05:48:5787a52310df65e9dcd7e81e71a670f660Executable exen/a
TrickBot
2021-03-24 01:27:16b5b8f4a1318013bed792d7199cd3ac5eExecutable exen/a
TrickBot