URLhaus Database

You are currently viewing the URLhaus database entry for http://45.147.229.175/root.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2116235
URL: http://45.147.229.175/root.exe
URL Status:Offline
Host: 45.147.229.175
Date added:2022-03-27 22:28:04 UTC
Last online:2022-03-28 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-03-27 22:29:06 UTC to abuse{at}combahton[dot]net)
Takedown time:1 day, 0 hours, 36 minutes Poor (down since 2022-03-28 23:05:10 UTC)
Tags:32 DanaBot link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-28n/aexe 2203373b86a55d95bcf44232991412d1b59b184e2be775ab8a20a287d34b770fn/a DanaBot
2022-03-28n/aexe 15897c42de40fdfb0cbacb658b97fc5e1b6264eb1b8774e756d8428825d41588n/a DanaBot
2022-03-28n/aexe 25288aadc92d11a16ab4ad15eb6abb1dbab655508b59cf2834ecad86eca6d5cen/a DanaBot
2022-03-28n/aexe 0019f7ece285e0389994c37db5c6181302b8380004b69625db99637278265313Virustotal results 32.35%
2022-03-28n/aexe 17d1b023cbe75dd59a3279a9b18aab378c09155d576edca70dd39d86bd70ad04n/a DanaBot
2022-03-28n/aexe ed37998f72cea2ba1772ef035c1c4a990f979a63b57b53f4e4be76bd7ea9dba4n/a DanaBot
2022-03-28n/aexe dc3d32b45e2a3ff1ff5e722741c6229c5f62b397a23dbc02990a6be7bb7bc718n/aDanaBot
2022-03-28n/aexe 77ddfe7f53f034e81b928dd6ad409afb6f2c582f3ddd204eedf376873b38c026n/a DanaBot
2022-03-28n/aexe 55908d94f8fa81eb165c1a63af63ad504b346c708eea710c7525e789ec96cffaVirustotal results 36.76% 
2022-03-28n/aexe c108f29a37f3639c95380534fd7f13c2b6dc42bead3545acc2446cdd6e93995fn/a DanaBot
2022-03-28n/aexe 86f73c1b17c696c267545e12e71d2a927c81a61d2448ef6ba090c7243a0a34fan/a DanaBot
2022-03-28n/aexe e0b1d407ce970837c18c18e6f492ce1d4f7173e68290ab6785f2bc8eba9df203n/a DanaBot
2022-03-28n/aexe 998cef12e0d501d1f8bb8db6cb65477bfc66a45c86f9bf5156a02afb40beb2b0n/a DanaBot
2022-03-28n/aexe 799519655c1e8ea6e7f66e59dced8ac74d3e6b4bc3b660d0483c1b022765715en/a DanaBot
2022-03-28n/aexe 88084338738f07b72949d7ac3d89f58e64c50192d604f6235ddf4c044af80bf7n/a DanaBot
2022-03-28n/aexe 6ee73d5e4fa4954957aad95443756f9be8fc1423cb7e83aad87048f7d2d970c0n/aDanaBot
2022-03-28n/aexe 81f56cdc1802346f3a7bd156ea1964b71922f11f2fd29fa36889616244d6a4b0Virustotal results 36.76% DanaBot
2022-03-27n/aexe 11d70988c6bb7174dd4050db008c278920f14cbfa54920655ad1bdbaee082700n/aDanaBot
2022-03-27n/aexe 0f8d2648166184bde6562f33b7e4b620313fe7a21746720d37594213fba7a604Virustotal results 37.14%DanaBot