URLhaus Database

You are currently viewing the URLhaus database entry for http://142.44.224.21/servces17.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1430297
URL: http://142.44.224.21/servces17.exe
URL Status:Offline
Host: 142.44.224.21
Date added:2021-07-06 07:14:06 UTC
Last online:2021-07-06 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-07-06 07:15:03 UTC to abuse{at}ovh[dot]net)
Takedown time:8 hours, 0 minutes Good (down since 2021-07-06 15:15:28 UTC)
Tags:32 DarkVNC exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-06n/aexe 4501a9320cfdb2c126e21510b32e9ccead1175a14f5b08197763dc9e356dc91dn/aDarkVNC
2021-07-06n/aexe 302f62827793127e3852b097e572fe0d65f3a2b5cfca165663d7e5e88a36323bn/a DarkVNC
2021-07-06n/aexe c525edbedea58f1a6eb7c877f27b753e915d9854e0378638ec1c5246801e0a20n/a DarkVNC
2021-07-06n/aexe 2c05cd58376851b90256c6131497d81a57a22a47d62cfd54882f91766cb2d59en/aDarkVNC
2021-07-06n/aexe ee783c78243f95e6128d37eaf546a5979213e85283814e8f8ca18e4a3c1a8fcaVirustotal results 33.82%DarkVNC