URLhaus Database

You are currently viewing the URLhaus database entry for http://sowork.duckdns.org/11d/solex.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1597404
URL: http://sowork.duckdns.org/11d/solex.exe
URL Status:Offline
Host: sowork.duckdns.org
Date added:2021-09-06 17:05:05 UTC
Last online:2021-10-12 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-10-11 12:06:04 UTC to noc{at}vdinetwork[dot]com)
Takedown time:5 months, 5 days, 20 hours, 23 minutes Bad (down since 2022-02-09 13:29:13 UTC)
Tags:32 exe Formbook link GuLoader link RaccoonStealer link RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-11n/aexe 099e02bedaed90dc85dfaab83e2bc65fc45cf9f1c53298fa3415d1c7e3b057c7n/aRaccoonStealer
2021-10-11n/aexe ae4d46e3c772093c5ad9ee27e412f11e6be6923a1efeca80b1dba5d1fef8f62en/aRaccoonStealer
2021-10-04n/aexe e4b26e2c09188228c4db16281887a17e90baaf95c7b691fa75d05af9f79ff20an/aRemcosRAT
2021-09-29n/aexe 5e0716efef9b86fed46cec2da9116f481add142b65aeb45be6d16666ac583404n/aGuLoader
2021-09-28n/aexe 2b545e3f6a3451fa26c928e77db0963a03b41d6b774c99cc79ca9353baa84527n/aRemcosRAT
2021-09-27n/aexe 7b3c49295c67d0de6a1739eca11609fc551805075fd66facfec8e2a2b6ca016cn/aRemcosRAT
2021-09-26n/aexe 8060a88a8253eafc4c38d56d58d8470b98765308aeafc1e873b95011cbb8cadfn/aRemcosRAT
2021-09-23n/aexe 397c1235b17a6b14fa61e480e59cf0d6c7d2cf7d633ae1c3957f82c23c985b95Virustotal results 18.46%GuLoader
2021-09-22n/aexe 1b0f25b9bf0c76f9a52d3f5952f47b203e7112c72f8234d51155442bddddd42fVirustotal results 7.35% 
2021-09-06n/aexe da71644ee66cad527be192aefdfb9e5c70f0977d111d95e3591c8221aca1ccfcVirustotal results 47.06%Formbook