URLhaus Database

You are currently viewing the URLhaus database entry for http://judithabusufaitdyg.duckdns.org/winupdate.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2251357
URL: http://judithabusufaitdyg.duckdns.org/winupdate.exe
URL Status:Offline
Host: judithabusufaitdyg.duckdns.org
Date added:2022-06-27 20:18:06 UTC
Last online:2022-07-26 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-07-19 04:27:04 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:1 month, 13 days, 10 hours, 41 minutes Bad (down since 2022-08-10 07:00:27 UTC)
Tags:32 exe LimeRAT Loda link Neshta RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-07-19n/aexe 15504193354c906ed2079878c0c104e3e420d887c5c5ab9fabed3d60afdb3bbcVirustotal results 72.86%LimeRAT
2022-07-13n/aexe 064c82c9caf9d7ac84081f1a3e7db2f8b53fe0b63b42f950700305cfb61912acn/aNeshta
2022-07-12n/aexe affe23699997f46b33a4f43d8558d7ec89603460ecea2f98952527dbaf09288fVirustotal results 86.96%Loda
2022-07-08n/aexe 9a125f79e4303e975d546b95d2fc83736bdd38fdfb18f6e1a3f2d76c16458d1en/a 
2022-07-07n/aexe d7580616774e8f0697b8f3b138ed40ce7390f33e9b69b0ea0f0c4ce27726cdb1n/a 
2022-07-06n/aexe cd6a8e6b17a1ecb5aafb24ef4f7ec0ba0be44508ea10dbde551e0037220571f8n/aRedLineStealer
2022-06-27n/aexe 78d88a6ac29625636a7433e358459a8cdfb837c853f6a149ceea102e707997f3Virustotal results 63.64%RedLineStealer