URLhaus Database

You are currently viewing the URLhaus database entry for http://silentlegion.duckdns.org/b.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1540376
URL: http://silentlegion.duckdns.org/b.exe
URL Status:Offline
Host: silentlegion.duckdns.org
Date added:2021-08-17 01:21:06 UTC
Last online:2022-01-25 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-01-25 12:07:24 UTC to audit{at}firstbyte[dot]pro)
Takedown time:5 months, 11 days, 10 hours, 48 minutes Bad (down since 2022-01-25 12:10:45 UTC)
Tags:32 CoinMiner exe RedLineStealer link Smoke Loader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-25n/aexe 499d13fc208546f11aca808ba0fbf365e9a4fa55285065254c2ae06e62352c90Virustotal results 32.35% SupremeLogger
2022-01-15n/aexe 75702b829cbd3d94bcb644dc82bc64eb92e186dcf5ff2cc54f46ab66c77b1f90Virustotal results 53.03% 
2021-12-16n/aexe e99befe316df1d1ed8ed92c083403bff09821b6a3895d4f78ff462c376306df7n/a 
2021-12-14n/aexe 003dc8f5904702f422550f3031ac5a45fb2d478682b73563eab3530f05de3aa8n/a RedLineStealer
2021-12-14n/aexe aaae3c6270dd40dea9bb17e13036ddb13f820c4e3ca44a9304a5d04237fa9bbbn/a
2021-12-14n/aexe 432f0ca0d93c7de0cd0791b1800f9643e10f3bdac32122a6994a9f498b8b1d51n/a Smoke Loader
2021-12-11n/aexe 5df26cbf5b6fbcd3e59b1ee1e3d12d0f372d4298e402ea62df847a33fa217cfdn/a 
2021-12-11n/aexe 3d143f4f1b99fe3792e132cc602c3e811b493a4ac6f6d0a78a9a3e4fff873137n/a 
2021-12-10n/aexe b57de1f6f0c41976b28cd20b30b19c0c49d56ae896878b38b1298213056b9b3bn/a 
2021-12-10n/aexe 1d57032ae8d8dce2472a891a726b779808e5298de9dae4a36a5f671e7490f7den/a CoinMiner
2021-12-09n/aexe 1cd0078be97de95fd1f6feaf704dadf22035b8c5013723528551c88209fe89dcn/a 
2021-11-30n/aexe 12e7b07a91914876396a4900e9d0fcf2f6b06bda5c77defd0293f05d2a0a52dfn/a 
2021-11-19n/aexe b3042205f2f1061ab5996356625f4f8c07dc5756385bd259b75fa5e27efb16b7n/a CoinMiner
2021-11-16n/aexe b271595aefd83bd28098ec572dc20b4af90ce336dd229f1f863660ac09e7448cVirustotal results 59.70% 
2021-10-30n/aexe aa80d4033a5c3a17dca903bdcf87c078ef6be9663c6e21a278d5d4cb9fdc6415n/a CoinMiner
2021-10-30n/aexe 0ab9d425abb0393e3507195c4187a8391a93a9f4c5c7e6083a63c3c8b68de630n/a CoinMiner
2021-10-30n/aexe 4494eef0783e136a383222e68dee735e1a3bbea6b0655de41700f7f50657502fn/a CoinMiner
2021-10-30n/aexe 5033549a5ea2065dcfa7aaf5b3ebe6d0d188b4a61b5351ec1130c461a75c3f36n/a CoinMiner
2021-10-30n/aexe 653405e15bba73133c10e0af602447cca5c735f1b3ba64038eff7fa03990153an/a 
2021-10-30n/aexe b1b91ecbab1b26511cf0716f54772bb9efd5e0a2d91a895425c39b1e3bc1a532n/a CoinMiner
2021-10-30n/aexe 073c2dc001c4ba9d53c734d9f8babeee3ac9f6646c94f7b6d8c1526835c485ccn/a CoinMiner
2021-10-30n/aexe 089f35e15f856eb0c536828e9dd92781299345c01a7dbd7c64cdc35bf859b140n/a 
2021-10-30n/aexe 0a2c9a187279a6ade795278928d4f1ec19c42bc302ffc6aa8c32ab175fffa28cn/a 
2021-10-13n/aexe b643d5ee1be492fcbfbfb4c9b9bf3da8460b74ab2097b96e6545318c92f2ee26n/a
2021-09-17n/aexe 715e1eb5414e749e16fb3999dda7bcf8405e6fb4e14e66ddcbdf20a2e1af89c3n/aCoinMiner
2021-09-13n/aexe 1a012590604643a5ad7fc60a8fd3c82a787a53a49ba7d3cba0b63e02e6ea70c6Virustotal results 39.71% 
2021-08-30n/aexe 4f9d6b736fbd00a1b8790ab77d6bde5b573b2177b7606724d2b6406839ceae3dn/a
2021-08-30n/aexe 6997b092bad4debd075be5e71976075f262e0e21f47e34db16ba1985d51d8017n/a
2021-08-26n/aexe 90e693c2ee07550354cd8ebf87756c33db4fe52cd72437aeefbdeb3161891b03n/a 
2021-08-17n/aexe b8ac779bad0064cb5e6371e1b1e745bbf9a7751f95d77729c2f461c5a2fc185eVirustotal results 65.22%SupremeBot