URLhaus Database

You are currently viewing the URLhaus database entry for http://142.44.224.20/servces.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1424944
URL: http://142.44.224.20/servces.exe
URL Status:Offline
Host: 142.44.224.20
Date added:2021-07-04 07:09:06 UTC
Last online:2021-07-04 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-07-04 07:10:03 UTC to abuse{at}ovh[dot]net)
Takedown time:4 hours, 15 minutes Good (down since 2021-07-04 11:25:32 UTC)
Tags:DarkVNC exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-04n/aexe c7db28aaba70134b5f02281dbf461a1d5efbd324fcd0990056d90a5c06068d4fn/a DarkVNC
2021-07-04n/aexe 0cc63a8c94f649b8d1a38763eed000d88db43b8a2014c0435c16a510707b15f4n/aDarkVNC
2021-07-04n/aexe 57cfe6895d7441ec163dfd2ee93092430fd5600324b3d3f713c792c2375a2a75n/a DarkVNC
2021-07-04n/aexe 1757ed2c04d0e2b53abe98a2ff5753ba4c6d0ff541c28f3c9df9022e2853f5a7n/aDarkVNC
2021-07-04n/aexe 0e987602142e521bab7a311b02a5856d89a07f41c74a3bbb2b8a2ecddcaa9655Virustotal results 33.82%DarkVNC