URLhaus Database

You are currently viewing the URLhaus database entry for http://umctech.duckdns.org/um/opr2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:200110
URL: http://umctech.duckdns.org/um/opr2.exe
URL Status:Offline
Host: umctech.duckdns.org
Date added:2019-05-22 15:30:26 UTC
Last online:2019-06-28 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2019-05-22 15:32:06 UTC to abuse{at}colocrossing[dot]com)
Takedown time:1 month, 7 days, 2 hours, 19 minutes Bad (down since 2019-06-28 17:51:36 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-06-12n/aexe b61bc1310be0c2efc2f70a3635d8bfb105d3b7aaa4e83cb3b7e92830d161c76cn/a AgentTesla
2019-06-11n/aexe 5cbd05d6ebd28522a64906857d5f4e9ce4e53a306b1585dd7dc9369aa18e398an/a AgentTesla
2019-06-10n/aexe f9fa8ca6b9fe292a762744d30631824465b919087fbbfee5333e19140facd191Virustotal results 11.59% AgentTesla
2019-06-10n/aexe e3108307ae4045f871941eb3b7a9813446da562a9c8a8986bd8d4d00bcbba648n/a AgentTesla
2019-06-09n/aexe 1299f6668b12c5a8534d934581b6b4f564047585e487bf12598f55e57d62cbd6n/a 
2019-05-22n/aexe 4cf926c479ff0789b42884d9282d92926e7e24670eb36a5ce454aa73d751b286Virustotal results 26.09% AgentTesla