URLhaus Database

You are currently viewing the URLhaus database entry for http://23.106.123.56/root.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2115813
URL: http://23.106.123.56/root.exe
URL Status:Offline
Host: 23.106.123.56
Date added:2022-03-26 22:28:05 UTC
Last online:2022-03-27 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-03-26 22:29:05 UTC to abuse{at}sg[dot]leaseweb[dot]com)
Takedown time:8 hours, 10 minutes Good (down since 2022-03-27 06:39:20 UTC)
Tags:32 DanaBot link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-27n/aexe 403da0c043c2998da98d36702af8795548dc51b836be342d9f2be808b07d6fb9n/aDanaBot
2022-03-27n/aexe 9310daf6d10f4fbfaf390e74bcf1c4d9acc023d7db3e26030f8772528572a22aVirustotal results 39.13%DanaBot
2022-03-27n/aexe 11661604424ce94b81ea61dfb5350005dfaeb81ea1f4b437e0f2a4ccabb9ef03n/a DanaBot
2022-03-27n/aexe d131ea54878f5844f2bc5104e8e936844cb6b0e9d56d50291997fd26fd5a08b8n/a DanaBot
2022-03-26n/aexe d3692d3823bd5e165d88e97bb2c2673489ff76fb873bb28543a2f233c9fe4ff9n/a
2022-03-26n/aexe c72aa9c4df96e6768a8a1db299a8e787ac729faa40c536fa4344f82d4670a947Virustotal results 37.14%