URLhaus Database

You are currently viewing the URLhaus database entry for http://152.89.247.33/1308.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2414166
URL: http://152.89.247.33/1308.exe
URL Status:Offline
Host: 152.89.247.33
Date added:2022-11-16 06:10:19 UTC
Last online:2022-11-16 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: jstrosch
Abuse complaint sent (?): Yes (2022-11-16 06:11:31 UTC to abuse{at}combahton[dot]net)
Takedown time:17 hours, 30 minutes Good (down since 2022-11-16 23:42:26 UTC)
Tags:DanaBot link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-16n/aexe 9b01805ba75f2f8445734e14d2e46f0c90a1aa1495daabe6002323b810fa45c3n/a DanaBot
2022-11-16n/aexe 02b20e4db8bf0d25be410c25b1d51a31eef5d6ff8e8231eb9b6f201ad95775c0Virustotal results 36.11%DanaBot
2022-11-16n/aexe a3dbe790fa3c5ba4de23b81f52d76a39284cfe75e2d1e467c1c13ef67f2b5fd2n/aDanaBot
2022-11-16n/aexe bacd86a7e6128f3189170dd34e9952a94d4ce2eeafb9ee476f184510f71031cbn/a DanaBot
2022-11-16n/aexe c8c043112b7f6ca1275a197add49d5d6d544f4290bd7a8da3ff5b24a11bf28b9n/a
2022-11-16n/aexe 5f68ee5d17015571bbd0707a228004e39d71d461ce0d783c7b90f48ede7a45f8n/a
2022-11-16n/aexe 17e42ec229e7ca91116e64747be7bcb02e3a1e17cf9b89b8b11adbfa5668d467n/a 
2022-11-16n/aexe 5ab27758ec65b98b31e5b337696cb09409a19e2563a4694c7da79cff7e894dedn/aDanaBot
2022-11-16n/aexe 2b610520f96a2e63100ec1433f822e7eeb2cf069b2006560ec42619c6dfe4d30Virustotal results 30.99%DanaBot
2022-11-16n/aexe 2faacc8c027b5a92c91cf2571561bc7177579123d2f92b9d863aec47ecd32882n/a
2022-11-16n/aexe 034a5406b76b4bd449648cd166a25e6d073b71a9a4ead464ef70bfcec5acfa7fVirustotal results 33.80%DanaBot
2022-11-16n/aexe dd9809306a89ea9eb3a8ee2dae32c41b4b769b4f12869930531d0bcafab6d4abn/aDanaBot