URLhaus Database

You are currently viewing the URLhaus database entry for http://172.86.120.229/nlaawi.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2387962
URL: http://172.86.120.229/nlaawi.exe
URL Status:Offline
Host: 172.86.120.229
Date added:2022-10-27 16:05:15 UTC
Last online:2022-10-27 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-10-27 16:06:13 UTC to abuse-reports{at}cloudzy[dot]com)
Takedown time:5 hours, 25 minutes Good (down since 2022-10-27 21:31:28 UTC)
Tags:DanaBot link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-27n/aexe 0f295d377540773127f73cf21c555c0358b8e28d8e74307535dd41839bf78f2bn/aDanaBot
2022-10-27n/aexe 1206052fbaa8552d703b6913ca35eb4f9653ea935048476b2ea7e92a439163e1n/aDanaBot
2022-10-27n/aexe 711d37b4962ad4756eadd8b899c296cd7d43326f0d70f35854b7955439fa8c3bn/aDanaBot
2022-10-27n/aexe fb1bd527586e3a82d89891d4dc6b925ec1d9ba75110bef638ff852bc14e0496fn/aDanaBot
2022-10-27n/aexe 6c4b2d812687391687ff74826ee6b83e0119579d43fe66b8a53fa835d35f11ecVirustotal results 50.00%DanaBot