URLhaus Database

You are currently viewing the URLhaus database entry for http://katchobinnas.duckdns.org/kat.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1150070
URL: http://katchobinnas.duckdns.org/kat.exe
URL Status:Offline
Host: katchobinnas.duckdns.org
Date added:2021-04-21 17:07:04 UTC
Last online:2021-08-24 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-04-21 17:08:03 UTC to abuse{at}amazonaws[dot]com)
Takedown time:4 months, 5 days, 6 hours, 18 minutes Bad (down since 2021-08-24 23:26:41 UTC)
Tags:AgentTesla link AveMariaRAT link exe SnakeKeylogger link Xpertrat

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-08-02n/aexe 7eb4302c92c1de3d5b2cd6467abe82e996c14aa6795f928434206b9ee62cbad0n/aSnakeKeylogger
2021-07-15n/aexe e3f01ed8d12f734d433783b0fe727e25e1a9a982a38e50fe72734c75c146df07n/aAveMariaRAT
2021-07-14n/aexe 7320273731dbce41f47cc62a196383cbe81764c7285277c153498818d1135b8fn/aAgentTesla
2021-07-01n/aexe 9fcb0cce3dce5ac243463c2fc5a1f4044ad9e92594723a76999a5faec55116acn/aAgentTesla
2021-06-30n/aexe 51297f05449c2fe207a4635e0d1123c137bfdfd97157e09b00af119733952197n/aXpertRAT
2021-06-29n/aexe 79aa4d81cf5455a126a2b7474067f392acc392370fa6ae0a62f7e1e0271775c2n/aXpertRAT
2021-06-29n/aexe c109fdc9eebddd35215c226381a886b4f2fdec8956ac9cfc428cbb6ef3405777n/aAgentTesla
2021-06-25n/aexe 06febadb1cc71ef3987c339b7c862ea4cd32656c372c4f266cd1af68c355a0c0n/aAgentTesla
2021-06-24n/aexe b6b8326fd527390a435242178b6a45a973c4516d831669ce7527c5d97e90ab10n/aAgentTesla
2021-06-20n/aexe 7fb990250eb44087277f87e8365a30dcdebba19c2c4c4c89287630ff329af399n/aAgentTesla
2021-04-24n/aexe 034f779a5a2a0436348e9a12d33fc925c688300c26561d8f413ffbfa89dd6c8en/aAgentTesla
2021-04-24n/aexe 8ef4a31bc2a6eacd381e90d8873c55da95a1ed26ec3240d38bfec7b0a25a6e6fn/aAgentTesla
2021-04-23n/aexe 8c63a7665a27d47e20bd74c4aaba5cf4a76d981bfd52820f935efd097dcfda3dn/aAgentTesla
2021-04-23n/aexe 4a11d85dec6ca99730c67c909898c5a057921b3befb7edee95836bcf0c09dbe5n/aAgentTesla
2021-04-21n/aexe 879811fbedbef41d9e338bebab74f5240924ef003d4631ef73ad6080b99b75c9Virustotal results 22.06%AgentTesla