URLhaus Database

You are currently viewing the URLhaus database entry for http://accessgrant.ydns.eu/office.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1398051
URL: http://accessgrant.ydns.eu/office.exe
URL Status:Offline
Host: accessgrant.ydns.eu
Date added:2021-06-25 14:59:22 UTC
Last online:2021-07-16 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-06-25 15:00:03 UTC to abuse{at}serverion[dot]com)
Takedown time:21 days, 8 hours, 20 minutes Bad (down since 2021-07-16 23:20:15 UTC)
Tags:AgentTesla link NanoCore link Neshta RedLineStealer link SnakeKeylogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-14n/aexe bff249e3363278aa671c0ea3eb9d596e1d8e265e908c3d22e2e887a441a652d3n/a 
2021-07-13n/aexe a73f2d92c3d48bad18d6a33530cedee50fb1495030c752d406045c113eeabd0an/aNeshta
2021-07-13n/aexe 011068b58f092a0ab48ded163dc2511839be72553c3d86f348d28e26ee59a873Virustotal results 28.57%SnakeKeylogger
2021-07-11n/aexe 1442ecf9c8781935c54f427f368462818900ebfa54672926130ef4e0b37dcac2Virustotal results 37.68% NanoCore
2021-07-08n/aexe 381e9692044f46f9a850f2f35b26473a63eec1a6486585fa49f4564c21c20cd6n/aAgentTesla
2021-07-06n/aexe f30d04cd12c5cab78668aa07ff17c4ffbdb4ae533e7a4c9e0ce50e7bf170aa14Virustotal results 29.85% RedLineStealer
2021-07-05n/aexe 26ae1aabf5b3b7236e691aa817a93741d0e825e2c7a39e1c31c694bee0eb7480n/aAgentTesla
2021-07-04n/aexe fe24a2b0b07d806e55c075d1c0de7f817b03f9faa23eeba5370ba6acd8272ecdn/aAgentTesla
2021-07-03n/aexe 27da66ed3e174f64d9dcff9795397922cef0af71e7fcfd91771e47a7bf377a88n/a RedLineStealer
2021-07-02n/aexe 772bc5203cddb673120c794d6fd7cbebef5016ac49090ed6c006bd66c0a4323en/aAgentTesla
2021-07-01n/aexe 2b93abcfcf4c5489dfbc9a9849b2743dd82b0f09f2b772cdc73f3f4721cb9d1bn/aAgentTesla
2021-07-01n/aexe 525e3d916bb14eeb8b678488d2d01c4f74dcf35ec84c1a4b4e56131a33364650n/aAgentTesla
2021-06-29n/aexe 65cd75c64354679cc597f59a5d9b618ac2e9ac6c26d5249705fb2a0739d07bb0n/a RedLineStealer
2021-06-25n/aexe 392ff0a8dc9670e54508c4834e303c5147070b857e3f8dc0e910f2630649d736n/aAgentTesla