URLhaus Database

You are currently viewing the URLhaus database entry for http://sowork.duckdns.org/11d/dyno.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1597372
URL: http://sowork.duckdns.org/11d/dyno.exe
URL Status:Offline
Host: sowork.duckdns.org
Date added:2021-09-06 16:47:06 UTC
Last online:2021-10-13 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-10-11 12:06:04 UTC to noc{at}vdinetwork[dot]com)
Takedown time:5 months, 5 days, 19 hours, 47 minutes Bad (down since 2022-02-09 12:35:16 UTC)
Tags:32 exe GuLoader link RaccoonStealer link RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-22n/aexe b5094678f221d1951715b487ba099a98d9d0007c79853600d81898f8d25f8233n/a RaccoonStealer
2021-10-11n/aexe 8b32464dfc8aa711a5469780f57ae24ddab4b65cd4eb2d9cb1d6797ce96de57fn/aGuLoader
2021-10-04n/aexe 6f476c63a6d699d1f0166313deb1e0f623c689882de8411bcd4f0b4f880526ddn/aRemcosRAT
2021-10-04n/aexe 3b6ea75a5628564667996ba672f4f8289d62a73aac96090024238f223db87e4an/aRemcosRAT
2021-09-29n/aexe 694b6c17b725903cf563928c0e6d0857900dfd1773a2e12c9acc8fd30a2f16adn/aRemcosRAT
2021-09-28n/aexe 47ab3e37baa7b201f6cb4ac0cfd7f486c018089220afee6a2f00bdbb50454feeVirustotal results 21.21%RemcosRAT
2021-09-27n/aexe c54b1a3af48ef7f70434b9e90c33b4bcdccfbd20339d8164e34957890c67f888n/aRemcosRAT
2021-09-27n/aexe 1f2f9b357003d7816259c172bff00bc8be6305247a94594de4eb9a7e7ecbb385n/aRemcosRAT
2021-09-23n/aexe b2573d8656ea0e2db5643a3aed1b8cbbd6f251cc4cff6c748f842e51b7829969Virustotal results 19.70%RemcosRAT
2021-09-22n/aexe 1b0f25b9bf0c76f9a52d3f5952f47b203e7112c72f8234d51155442bddddd42fVirustotal results 7.35% 
2021-09-06n/aexe 6cbaf335b0737ddf3f782688324856ef573d1978897299461f7a43c8efeaa008Virustotal results 41.79%RemcosRAT