URLhaus Database

You are currently viewing the URLhaus database entry for http://216.170.123.13/nass.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:329293
URL: http://216.170.123.13/nass.exe
URL Status:Offline
Host: 216.170.123.13
Date added:2020-03-24 16:37:04 UTC
Last online:2020-04-12 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: p5yb34m
Abuse complaint sent (?): Yes (2020-03-24 16:38:02 UTC to abuse{at}colocrossing[dot]com)
Takedown time:18 days, 15 hours, 28 minutes Bad (down since 2020-04-12 08:06:02 UTC)
Tags:exe GuLoader link NanoCore link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-04-01n/aexe 5fe88d0edf17e2bcbbc22d30230f698c5229e31ca58853e9dc86b8e71cc8383an/aGuLoader
2020-04-01n/aexe c6b43505d40cb5d45abb2d4f79e6b83c7c1c0cae54e2696348bcfcf3fecdcaf8n/a GuLoader
2020-04-01n/aexe 19b3833a31ab8c55baa97051689507e29b3599df0f2a4d6f8a06d2ce1db2cc6dn/a NanoCore
2020-03-30n/aexe 6fdc8ad458c5b60a15774baef1acff96af05216b279754c5188c63ee542a82fen/aNanoCore
2020-03-25n/aexe 98f58666a225a17e19aac47c6d4169aff52fc92a557165f453121ddee78351cen/a GuLoader
2020-03-24n/aexe 5d615e82f2b0a90f4d7b50e17fa070d6ce5684bde0a5de1d0661f2d166af964bVirustotal results 6.94%GuLoader
2020-03-24n/aexe 33414949d9094cd4837b765b9164d860ad6785f06de72cd0cbc99ddef8de867fVirustotal results 16.44%GuLoader