URLhaus Database

You are currently viewing the URLhaus database entry for http://185.173.34.105/baiden.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2494231
URL: http://185.173.34.105/baiden.exe
URL Status:Offline
Host: 185.173.34.105
Date added:2023-01-02 07:54:13 UTC
Last online:2023-01-02 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-01-02 07:55:06 UTC to abuse{at}heficed[dot]com)
Takedown time:15 hours, 29 minutes Good (down since 2023-01-02 23:25:04 UTC)
Tags:DanaBot link ee

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-01-02n/aexe 963ae963709b17b052f3681dc033ee72d4ca964b00cc6b06ba09671569e7b14eVirustotal results 50.70% DanaBot
2023-01-02n/aexe db6a84ae512671b7f69ecc37f63ddbb321029fd9fc521c54978ae778db115252n/a DanaBot
2023-01-02n/aexe 9fcf9728beb1be6a482cbfa875337235121ee3638a19d28ee43e61b9e66e6aebn/a
2023-01-02n/aexe f775c90b057e03b50d5348f7a043547de65ea9a526123551fead2e3a61b32334n/a DanaBot
2023-01-02n/aexe fd1fd9d508e20eed4e9d1007e474ff27aec3cdc60a8b320b0b3537db8ad0d404n/a DanaBot
2023-01-02n/aexe d2846a95d8bc96b19df66a573877878830464af25f0f461408ed8cabd90a14b7n/a DanaBot
2023-01-02n/aexe 56daac43baae464ab5000e949b587c3af4bf4864bdda8131b23b22c468f1138en/a
2023-01-02n/aexe b0b84af4c80e573bb14272ca21b793013e49f0ee4ea2512a22ee65800d446934n/a DanaBot
2023-01-02n/aexe c1caac58e614931c517666747eec84548ca762fff9744c47ed6cfe162c511331Virustotal results 40.85%DanaBot
2023-01-02n/aexe fbd172f7f6c9e4b8c915d7ff24d40ddcad456223407e383b2230f24e046031bbn/aDanaBot
2023-01-02n/aexe 2ee350a3c3c03283a1458ff5e3e142d91b46a8fecd846ec8df0d1edca7c1e4cfVirustotal results 44.44%DanaBot
2023-01-02n/aexe 4ba96ecdcdfa746de28a0ee3ef474842e829917c9486ace35ec4cc2fa1ad956fn/aDanaBot