URLhaus Database

You are currently viewing the URLhaus database entry for http://23.106.122.132/svchosts.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1892545
URL: http://23.106.122.132/svchosts.exe
URL Status:Offline
Host: 23.106.122.132
Date added:2021-12-17 06:50:06 UTC
Last online:2021-12-17 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-12-17 06:52:20 UTC to abuse{at}sg[dot]leaseweb[dot]com)
Takedown time:7 hours, 29 minutes Good (down since 2021-12-17 14:21:39 UTC)
Tags:DanaBot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-17n/aexe f73da0ec6c710f682fb76142a0c856d93a0781a422c42d441574a3423e257786n/a DanaBot
2021-12-17n/aexe 1458cc1cf26e0ad4690192cbfa94d78cc1439fbf785ba0613ce8c98791e31ea3n/a DanaBot
2021-12-17n/aexe f7c452fd0d9049e783c3f645a07334206df021d0b1b88fae356a78f5c21b8f8fn/a DanaBot
2021-12-17n/aexe 6975d41b8936723fc9483a44f1589a3dc72c69f8a731582149468e9be6495659n/a DanaBot
2021-12-17n/aexe cf08f80fe430cc666d3c25a939d49976129da08db2c467375eada6e041efd432n/a DanaBot
2021-12-17n/aexe 017190d28b8fd79edc04d0efc71bb66561a80f6908e979d451d00f8d7339a7ddn/a DanaBot
2021-12-17n/aexe 6777ebe2c39e27f0bee03860b02a8ac080e3ab98375d933d6bb4ca792cc046ban/aDanaBot
2021-12-17n/aexe f60d2c6bda016a6fd0d165a5ee38ed4dceb39c9835ce0dfb6d5b1ddf31dd6f5eVirustotal results 38.24%DanaBot