URLhaus Database

You are currently viewing the URLhaus database entry for http://23.106.122.191/local28.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1052337
URL: http://23.106.122.191/local28.exe
URL Status:Offline
Host: 23.106.122.191
Date added:2021-03-07 11:02:15 UTC
Last online:2021-03-07 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-03-07 11:04:05 UTC to abuse{at}sg[dot]leaseweb[dot]com)
Takedown time:4 hours, 34 minutes Good (down since 2021-03-07 15:38:06 UTC)
Tags:DanaBot link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-03-07n/aexe 6fe903976f90879844810fff30d0bffb74fd34152b7607e4e4408335a72aad9dn/a DanaBot
2021-03-07n/aexe 7a258c0d4948b9229793e4b966cdfd6b12b3cc5ca000d6cc21d43e4bca2ab3d1n/a DanaBot
2021-03-07n/aexe 7417145dc245c0a3e600a937618217b62898fe121aeba83bdc37c9f7c9b5a736n/a DanaBot
2021-03-07n/aexe f2b2650b6b41eacb14a473697ebc470791cf7937f7020f348c5a979b49684e7bn/a DanaBot
2021-03-07n/aexe 076f0fd115de1f3ee238540b9b65f91aed3fe9285f4f3eab0de57cb102d4b389n/a DanaBot
2021-03-07n/aexe d2ba18358b1edbac5cdb875761367ce6f88ef0e61d749357a259988d15d1bc17Virustotal results 29.41%DanaBot
2021-03-07n/aexe 6ca1ef8e8c17e600fa0fe3a18a048bc7f5b5adbaafb2fabe8eebe21fe039439en/a DanaBot
2021-03-07n/aexe 054f463e3c9bd3cdec357069abf5ab988742bcc289c691d7da10be80ac599602Virustotal results 28.57% DanaBot
2021-03-07n/aexe 856477b9dcf2b37c6307ba0fcb707ba8d32cb64548b4f8281ffa3d600d090decVirustotal results 28.79% DanaBot