URLhaus Database

You are currently viewing the URLhaus database entry for http://androidmedallo.duckdns.org/done.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1470374
URL: http://androidmedallo.duckdns.org/done.exe
URL Status:Offline
Host: androidmedallo.duckdns.org
Date added:2021-07-21 08:21:14 UTC
Last online:2021-10-16 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2021-10-16 10:42:04 UTC to abuse{at}frootvpn[dot]com)
Takedown time:2 months, 27 days, 12 hours, 2 minutes Bad (down since 2021-10-16 20:25:03 UTC)
Tags:njRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-07n/aexe bce1cfbca7748bc0ff26b042668feddb6f4db2f44e10637b781cfe2394ff6414n/a
2021-10-02n/aexe bd5fa7ccde2dbc145685b36d66c3c6161e7e780308bd6ec29666139908e7db26n/anjrat
2021-09-15n/aexe 51324ce0d6bc7c8668dea9b0bcc31048038723480ca16be17e6234a7cc88c391n/a njrat
2021-07-30n/aexe d2e347f7ecbcb94a4fe2e0ea86f92d0f60321be94441265b97f0e0b212c0efbcn/anjrat
2021-07-29n/aexe 989a832dd6395528e5373e6fd04432a48843c299b53e8aade6142a6fee6dec94Virustotal results 39.13%njrat
2021-07-21n/aexe 3582b41cef347b9aab950ae01a42ecf76d9d13b1b1a4601fc03bc3ee4535fa4fVirustotal results 45.71%njrat