URLhaus Database

You are currently viewing the URLhaus database entry for http://80.209.233.231/nscvhost.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1641939
URL: http://80.209.233.231/nscvhost.exe
URL Status:Offline
Host: 80.209.233.231
Date added:2021-09-24 06:14:04 UTC
Last online:2021-09-24 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-09-24 06:15:03 UTC to abuse{at}iv[dot]lt)
Takedown time:13 hours, 44 minutes Good (down since 2021-09-24 19:59:45 UTC)
Tags:DanaBot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-24n/aexe 8174054c67035ea2aef476a22bb14270d36299cc62adfd2dc2900a7686ce156en/aDanaBot
2021-09-24n/aexe 867317f0875ba0635d62393278994b110ea94179d6e736fa7891a83983822143n/aDanaBot
2021-09-24n/aexe 73e761de4a8be29d7dc04e48a47f417917cf2f37a27dfb9db45069d4ccb66cecn/aDanaBot
2021-09-24n/aexe 34f3e9fff45b86f0d41196592ac0c8df6852bae2724aad54f822f8f5983a702en/a DanaBot