URLhaus Database

You are currently viewing the URLhaus database entry for http://23.106.124.90/rokyh.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1715155
URL: http://23.106.124.90/rokyh.exe
URL Status:Offline
Host: 23.106.124.90
Date added:2021-10-26 09:09:06 UTC
Last online:2021-10-26 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: benkow_
Abuse complaint sent (?): Yes (2021-10-26 09:09:20 UTC to abuse{at}sg[dot]leaseweb[dot]com)
Takedown time:9 hours, 43 minutes Good (down since 2021-10-26 18:53:15 UTC)
Tags:DanaBot link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-26n/aexe d909d0ee7d46bee49c5496a3b5f7cc367a4ad8ce8448e65d83c497be9891cd5fn/a DanaBot
2021-10-26n/aexe a605842af3550c89bf0180e8a5de77978f76d5903aa2e1e7aa1aba73c304713dn/a DanaBot
2021-10-26n/aexe 73f7dc55047b1ddba4e56b62e9db3ffa8f62a405e6df72a4924122f5b5c1c546n/a DanaBot
2021-10-26n/aexe 8151c5a824e9435ed05494cf58a2df2e81a10ba626cc2b7591131f1589e9bc40n/a DanaBot
2021-10-26n/aexe 0d515018518846d2de42b00d2bc15a8b8f5611d43a4270cf86ee5ab2c44f95f2n/a DanaBot
2021-10-26n/aexe 7a6db00e7ac6b85de2fb6bd3ff9789fa597dbd81d25ba228111f4a97719c00a8n/a DanaBot
2021-10-26n/aexe 1bd2a4640d342d700c2ab31b9a32a328eb1ce92b4bf432e026b0b1169aab2c4en/a DanaBot
2021-10-26n/aexe 11da67d2ec898827753f51e2bd4fc8329a5b29f33bcd1494f996c311bac93e7cn/aDanaBot
2021-10-26n/aexe b01e6e1288860dbdc71c130c005c342b01b8febe90a59a52efadeb7e7f821964n/a DanaBot
2021-10-26n/aexe ba58e003883e6ef7e4e1b5289fc201a8e5eaeec85fe2f3809e68aad8439066aen/aDanaBot
2021-10-26n/aexe 5da0e1ac2473448b7a68d276295d6da66d4858d3c5401a0c558e14dd17048967n/a DanaBot