URLhaus Database

You are currently viewing the URLhaus database entry for http://213.227.155.193/underground.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2381482
URL: http://213.227.155.193/underground.exe
URL Status:Offline
Host: 213.227.155.193
Date added:2022-10-21 08:00:05 UTC
Last online:2022-10-21 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-10-21 08:01:11 UTC to abuse{at}nl[dot]leaseweb[dot]com)
Takedown time:10 hours, 3 minutes Good (down since 2022-10-21 18:05:09 UTC)
Tags:DanaBot link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-21n/aexe 11ee9d9a7bffb5ab3e5127f934e4aa7d2bad4adc4af0a207697e309635cd4d14Virustotal results 44.44% DanaBot
2022-10-21n/aexe 825d8e7afb11042951c61102a283326dfac5f1b0c6f990aadde69410ba250bban/aDanaBot
2022-10-21n/aexe 0d75ee72b5ee8528fddab43bf8aa7d1e23bfba8678c7ad9f0fef924f3104cc54n/aDanaBot
2022-10-21n/aexe 8b1bf37f63243258a81500a89bd8524f701d050887322f5dd3d613b8f2343070n/a DanaBot
2022-10-21n/aexe d79f5e45a2fbd17a0d356f6a98ff3055feaa93386e96eaca0cc09fe102fa6b64n/aDanaBot
2022-10-21n/aexe 3b6d4fa25e758b0723d6fe3257983eb5b55a2c3e9771f4b5a5566653e813fc8aVirustotal results 38.89% DanaBot
2022-10-21n/aexe 1445cc1e3676b05b4a1d5bdb3da5c9d38ccd9dedc99537e05d61c594d65d5955n/aDanaBot
2022-10-21n/aexe f81f50dd1e11702ccdc012a46cf2d1b1f9952c2097330961dd2b40677cb04af0Virustotal results 40.28% DanaBot
2022-10-21n/aexe f1fe57a7bfb7d300e0cfed209e3ee697efbd3c7ce27540fbf84f066cdaf9b57dVirustotal results 46.48% DanaBot