URLhaus Database

You are currently viewing the URLhaus database entry for http://oreokitkat.ddns.net/downloader/svchost.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1896738
URL: http://oreokitkat.ddns.net/downloader/svchost.exe
URL Status:Offline
Host: oreokitkat.ddns.net
Date added:2021-12-18 22:04:04 UTC
Last online:2022-05-12 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-05-12 14:21:07 UTC to abuse{at}xs4all[dot]nl)
Takedown time:4 months, 24 days, 16 hours, 20 minutes Bad (down since 2022-05-12 14:27:17 UTC)
Tags:32 exe IRCbot

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-05-10n/aexe 4a0edec444b95ea38bb912f1f7fd277ddf0fd7612675eff98071d554273af95dn/aIRCbot
2022-05-09n/aexe 15770811a577cda745bb7135ef693fd49ff94f6b44c4783d08c20b8975882dc6n/a IRCbot
2022-05-09n/aexe c5c9c20c1b3bfcd31ec2d363dbf9ec27aea963c41a200cdf519e94f715cffb33n/a IRCbot
2022-05-01n/aexe 85543698ae27ded528869d575d9df25cda27b2edec65b71a4413259771b3953dn/a IRCbot
2022-02-22n/aexe e7771858fb6b3c616b65c1daaf2b82aa74532b5a0888908d5342d8fe7e071403n/a IRCbot
2022-02-08n/aexe b56defac42f0f7962a918c92385bd6784b626527c1e83a48181f201e2dfdf95fn/a IRCbot
2022-02-04n/aexe 799679c3936225db0d27ec0acad41830100119ec9d682cef272111523b2f2468n/a IRCbot
2022-01-29n/aexe edbf51d69b38958bbfaef71bf0037907d824b24e18efd5e25735362c0dd6bdc0n/a IRCbot
2022-01-18n/aexe 2d6bee9e6b07812859de7b7bee385c725d7b1e394270229bfe4b4fe1245e4497n/a IRCbot
2021-12-18n/aexe 0db6c2a5f841c34c9ae8974c40c6f9509276ac21367072d3b2f944bf9a21cb36Virustotal results 55.88%IRCbot