URLhaus Database

You are currently viewing the URLhaus database entry for http://katchobinnas.duckdns.org/obi.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1150069
URL: http://katchobinnas.duckdns.org/obi.exe
URL Status:Offline
Host: katchobinnas.duckdns.org
Date added:2021-04-21 17:07:04 UTC
Last online:2021-08-24 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-04-21 17:08:03 UTC to abuse{at}amazonaws[dot]com)
Takedown time:4 months, 5 days, 6 hours, 12 minutes Bad (down since 2021-08-24 23:20:30 UTC)
Tags:AgentTesla link AveMariaRAT link exe NanoCore link SnakeKeylogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-08-03n/aexe 173aa58b574b905cf4c9182d9e1c56d400d477d386d928887c6471dfdf19688bVirustotal results 57.14%AgentTesla
2021-07-14n/aexe 58e7c1702583c96deff86dea74d58b0abbd68125448cb9aaf25143e82daef3d1n/aNanoCore
2021-07-13n/aexe e150f981d43106895ce64ebce7b41ae17b0eed49baa4cfc0d8d09c98dd208e8fn/aAveMariaRAT
2021-07-13n/aexe 94c04d6b5f82d551838ed5ea1cebc1d312991640a368ac10df709704b327a880n/aNanoCore
2021-07-13n/aexe ffa6bd14feb2c02a38ebb070805becef8794e8900be26bbb3e79070fdc01b1ddn/aNanoCore
2021-07-10n/aexe aebb7fe3721ab50e0758981b2817beee86fba2797abea2bd19192abc7811761dVirustotal results 66.67%SnakeKeylogger
2021-07-01n/aexe 884639b2dc1f06412d6a7ce5e3aaefdfe3bdb3e346ac7a04bca596e07754ff78n/aNanoCore
2021-06-30n/aexe 99d0493be000e012593aca3339e9f6dd2bd053c38275afcf8165a1a7d24198a9n/aNanoCore
2021-06-29n/aexe e0616714772d15d3118f1ee3b1c71ba8fd66b3e80e844e66e3550a7e7b6fe01an/aNanoCore
2021-06-29n/aexe d26e5453281bd521ba914d6dbbcfa8d1ef37cad2e2f91ed19284b0000ad67b8dVirustotal results 90.00%NanoCore
2021-06-29n/aexe 57300e5d3030d478cb3e965cc603e004d1f1c8e246c841c5181f326c5b09803cn/aNanoCore
2021-06-24n/aexe c62470b8c29852980c3c6f0e56bd70593d696605ce7c817fb7124673327ee015Virustotal results 42.86%NanoCore
2021-06-20n/aexe 18ced60c11da4be44329f820ed92543984e686e39a97a1896a9ae41ea4c20933Virustotal results 27.54% AgentTesla
2021-04-24n/aexe 5935c56295e4b48df64c472820ca5d259e7159761ee30536275832a6f7898014n/a 
2021-04-24n/aexe 775c4c83ada8ad92ee38c54eed5258446605a4ba50883903d2900f39beb8f2c0n/a AgentTesla
2021-04-23n/aexe aeb3ee199361c07c05d92f5b40c010bfebda15a3429364ac6ab5f4e7b203afa9n/aAgentTesla
2021-04-23n/aexe 0d0bf170253eb2be553d5c0cbea413b712d2205ed5d2c4014a716ba51171d65cn/aAgentTesla
2021-04-21n/aexe bda6d3b18fa97de048056b1b52ae6873b7b1cd2742b16282ec1e6e0d23b65a3dVirustotal results 25.71%AgentTesla