Browse Botnet C&Cs

You are currently viewing the database entry for the TrickBot botnet command&control server (C&C) 89.191.234.91. You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


Host:89.191.234.91
Hostname:khavm.jj
Status:Offline
Spamhaus SBL:Not listed
Malware:TrickBot
AS number:AS40824
AS name:WZCOM-US - WZ Communications Inc.
Country:- US
First seen:2019-10-19 15:55:36 UTC
Last seen:2019-10-27 03:28:32 UTC
Last online:2019-10-29

Malware Samples


The table below documents all malware samples associated with this TrickBot botnet command&control server (C&C).

Timestamp (UTC)Malware Sample (MD5 hash)VTHostPortSignature
2019-10-27 20:42:41a3449f52534ce02065fb47ebce21c110Virustotal results 40 / 69 (57.97%) 89.191.234.91447TrickBot
2019-10-27 03:37:57c93640625a7a7328f41c943ad21c65e5Virustotal results 53/70 (75.71%) 89.191.234.91447TrickBot
2019-10-26 08:25:511da235acd4b9eb809197c69c93dda605Virustotal results 53/71 (74.65%) 89.191.234.91447TrickBot
2019-10-22 02:54:407b1b18959640149c4fab91504cab9830Virustotal results 51/70 (72.86%) 89.191.234.91447TrickBot

# of malware samples: 4