URLhaus Database

You are currently viewing the URLhaus database entry for http://lndcin.com/kit/a.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2390740
URL: http://lndcin.com/kit/a.exe
URL Status:Offline
Host: lndcin.com
Date added:2022-10-31 06:06:13 UTC
Last online:2022-11-18 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-10-31 06:07:12 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:18 days, 4 hours, 18 minutes Bad (down since 2022-11-18 10:25:31 UTC)
Tags:AveMariaRAT link exe NanoCore link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-18n/aexe 9d9f2c64c077d3240f88906f3e73559c5bf554809a1e8974f8c8f28704c576eaVirustotal results 25.71%NanoCore
2022-11-14n/aexe 3f0a89e3647d4ff575fc0c8db1ea5e9f7dbf2c0041f90ec2ef26c7eab69b34f8Virustotal results 39.44%NanoCore
2022-11-10n/aexe e1691661492c90c09468d610d7172274bb94789da8edd4b42e33604afeeea194Virustotal results 30.99%NanoCore
2022-11-07n/aexe 0ff450d6d7270655536ace71af2d4fe87c832b89597ce2c67a52aabd94f54cd6n/a AveMariaRAT
2022-11-05n/aexe d3b89309f9088554afe3ce791ddb2eb93a4dd1945fcffae7221500514b730791Virustotal results 29.17% NanoCore
2022-11-01n/aexe 757d201efcd23832275a776938bee5e4af405666bde0876172c730faff12832fn/a
2022-10-31n/aexe bf75723c7ecbfc9b57ce4e725f612cedd611e69b38fa59b31b0559e054075326n/aNanoCore