URLhaus Database

You are currently viewing the URLhaus database entry for http://213.227.155.16/underground.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2355191
URL: http://213.227.155.16/underground.exe
URL Status:Offline
Host: 213.227.155.16
Date added:2022-10-10 14:09:05 UTC
Last online:2022-10-10 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-10-10 14:10:12 UTC to abuse{at}nl[dot]leaseweb[dot]com)
Takedown time:7 hours, 17 minutes Good (down since 2022-10-10 21:27:47 UTC)
Tags:DanaBot link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-10n/aexe 9da0b7ee48275a3ef67234ed75a6734c2fdc6665b46c200bbefe961524664f9bn/a DanaBot
2022-10-10n/aexe a3702861321d7fc87fbd84d5c374a7284162788cc5e7dea8fcba2f2ea719af74n/a DanaBot
2022-10-10n/aexe 38dfcac78145a49ef6a95a11657e76ad7e09b66fde692ccfd24ec099df5ac283n/a DanaBot
2022-10-10n/aexe 52bc53ad95ba364ac8452d055bac508effb16c540466a36c75486f07cfe57f83n/a DanaBot
2022-10-10n/aexe bbb5ea5b5258fcd9a920e525af4ea3806f7d45733f4a675fbc5c0593cff2cb16n/a DanaBot
2022-10-10n/aexe 5bec061168fbe49fd997f510a4ced25534bf04cb36bc524767c0451dc4f51708Virustotal results 31.94%DanaBot
2022-10-10n/aexe fe6e6d5a27213b800e118188f7e0375537ed109c2c5ded0c9e3915f70be64ed7Virustotal results 47.22% DanaBot
2022-10-10n/aexe 4c44dd2806d0afbe3f1472f9b19377661f8cb6f88f6053061982c4a263a57ae5n/aDanaBot