Browse Botnet C&Cs

You are currently viewing the database entry for the TrickBot botnet command&control server (C&C) 92.38.135.205. You can get additional information about this C&C here, such as first seen, last seen and associated malware samples.

Database Entry


Host:92.38.135.205
Hostname:korein.tz
Status:Offline
Spamhaus SBL:Not listed
Malware:TrickBot
AS number:AS199524
AS name:GCORE
Country:- KR
First seen:2019-05-17 07:37:13 UTC
Last seen:2019-05-17 07:37:13 UTC
Last online:2019-05-27

Malware Samples


The table below documents all malware samples associated with this TrickBot botnet command&control server (C&C).

Timestamp (UTC)Malware Sample (MD5 hash)VTHostPortSignature
2019-05-29 04:56:5553af54255f372fe45b69950a6cfd3cb8Virustotal results 50/72 (69.44%) 92.38.135.205443Heodo
2019-05-28 23:48:14570d81abf5e5055fb8e7d8e896c8e15eVirustotal results 43/71 (60.56%) 92.38.135.205443TrickBot
2019-05-27 13:46:072e2f0144b15a02da23c2a658f491e82bVirustotal results 45/71 (63.38%) 92.38.135.205443TrickBot
2019-05-25 09:54:58750655c422858f44bc85498207f1d6bbVirustotal results 32/71 (45.07%) 92.38.135.205443IcedID

# of malware samples: 4