URLhaus Database

You are currently viewing the URLhaus database entry for http://195.181.240.2/ephost.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1087755
URL: http://195.181.240.2/ephost.exe
URL Status:Offline
Host: 195.181.240.2
Date added:2021-03-24 07:40:07 UTC
Last online:2021-03-24 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-03-24 07:41:02 UTC to abuse{at}iv[dot]lt)
Takedown time:12 hours, 49 minutes Good (down since 2021-03-24 20:30:17 UTC)
Tags:DanaBot link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-03-24n/aexe bd1de3d7111a675581c18329adbabb8d60026384cd4fe8f031d741e676784f95n/a DanaBot
2021-03-24n/aexe 37b4e5b93f8010a715d976bbce6b00db22b4b93c0b4c951604d52774fb2e7ea9n/a DanaBot
2021-03-24n/aexe e3c90a2f166be573ce70806f67e4252e8ddb0cef41908cd75a746aad87f0b72fn/a DanaBot
2021-03-24n/aexe 04d36c898ddae055732cfc7452363602e204c1d5ff662be0c97816a6f5de8643n/a DanaBot
2021-03-24n/aexe d2388caf5ad6459cecac9c27c1b3bc43dc74b9ed2f783c94b90e7d65ec54d0f4n/a DanaBot
2021-03-24n/aexe acfb756ebcc92912142f55d95bb1b180b9121f2ba074de115c6babf8b046bc8en/a DanaBot
2021-03-24n/aexe 0ea394fc0543a4b5979e6958b32fc24b1b587cd55e8a6a61b6a2c220c7dad0c8n/a DanaBot
2021-03-24n/aexe eb25f335db9e9daaa2cad190a2dec8e25c28cfc20dc7f479ba80d95e2ee6a9a5n/a DanaBot
2021-03-24n/aexe 753ac1420c0190a0c9169577948f4157f1b9372560317f2df31d9572f2a0900an/a DanaBot
2021-03-24n/aexe e351ef452cb1f685dbe18a12db36125592f3a7950a18a64325e0bac05ccddb48n/a DanaBot
2021-03-24n/aexe 3d84cdcd6300b3e888ec383bd863149545982eac38e368e8740826e642262de0n/a DanaBot
2021-03-24n/aexe 17c8e40a4ad5f5d4d1458d0457b44cde19c697f8a329d48a28ceffebf53d1067n/a DanaBot
2021-03-24n/aexe d11b2fa1e3d6ff91802c9ea4c1115471804aed46aed8e5f81701442727d989a5n/a DanaBot
2021-03-24n/aexe b2d6f2fbee9cc367cd5f519e52457481d709b0040182c78ceed58312c2be73c5n/a DanaBot
2021-03-24n/aexe 6b5ac8a36a41a1220a049752119417478afd1ac433ac5b2da0e7c9560b38c52en/aDanaBot
2021-03-24n/aexe 834e95a8300e42509304fa7fe76cfe7678341bcf1769a90de14eaa382c7d88b8n/a DanaBot
2021-03-24n/aexe 5288d023c4a8127ed105f7d8b9142aab47dc505efc5b6a81e8c9367f0465c03an/aDanaBot
2021-03-24n/aexe 0aeac7d32fcb6e48bd9f2a73d6a01a76472ce4ce7962f99979e5f2c2d150fe39n/aDanaBot
2021-03-24n/aexe e1043b597d99a6553919b8e0d8e265aa6dd2f2004d63c57686d3e4dfca13505en/aDanaBot