URLhaus Database

You are currently viewing the URLhaus database entry for http://103.205.253.251:99/buding/AccountBind.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3719390
URL: http://103.205.253.251:99/buding/AccountBind.exe
URL Status:Offline
Host: 103.205.253.251
Date added:2025-11-29 05:50:12 UTC
Last online:2026-07-21 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-11-29 05:51:15 UTC to ipas{at}cnnic[dot]cn)
Takedown time:7 months, 24 days, 0 hours, 29 minutes Bad (down since 2026-07-21 06:20:17 UTC)
Tags:huntio opendir Worm.Ramnit

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-07-21AccountBind.exeunknown 1f195f34bb080030f5f9df18a9e2f55a2145ab64d55dba85205b5ef167664496n/a 
2026-07-20AccountBind.exeunknown 141409b0ff151100af66f30e4899aa52bc155cbdf661d2adfac774ed079a6940n/a 
2026-07-19AccountBind.exeunknown bb9be92bbead9c9114600e87546e1476b3435f23f1f88aa2b5ddbd0efad5998an/a 
2025-11-29AccountBind.exeexe 32957fefa181f01f922b53877b2a96583fc9e7b57fb72f63c3011d012b6e8b97Virustotal results 87.50% Worm.Ramnit