URLhaus Database

You are currently viewing the URLhaus database entry for http://wetransferdownloads.duckdns.org/ftp.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:699333
URL: http://wetransferdownloads.duckdns.org/ftp.exe
URL Status:Offline
Host: wetransferdownloads.duckdns.org
Date added:2020-10-16 05:23:18 UTC
Last online:2020-11-02 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Racco42
Abuse complaint sent (?): Yes (2020-10-16 05:24:02 UTC to abuse{at}shinjiru[dot]com[dot]my)
Takedown time:16 days, 22 hours, 35 minutes Bad (down since 2020-11-02 03:59:27 UTC)
Tags:AveMariaRAT link AZORult link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29n/aexe 961fd774fb5def2cb861b6cf22941506d4336e4924e343c02eaf30b9216bedc6n/aAveMariaRAT
2020-10-28n/aexe b50f9caa6df41cf34a52f45f989dc38ba037fd68535f6d7015fe602c826b0c1cn/aAveMariaRAT
2020-10-28n/aexe 9bbe3fd9a991edfa2f20c9afeb7f6eeb8ac34adfde9d6a5320aed218b1785281n/aAveMariaRAT
2020-10-27n/aexe 758aef9d9d8009bb00e0ba970d95c1e938b7db07f6a0141d8888a6c71e317235Virustotal results 23.53%AveMariaRAT
2020-10-26n/aexe bf97a4d3f287f442925ba3af63741dbaa594e5ad99b6574fd660e1bbe6f8733bn/aAveMariaRAT
2020-10-26n/aexe 636da001ec9866d90d2029492c8330a69ac87eff8a9258fcf2df66ff275951cfn/aAveMariaRAT
2020-10-21n/aexe 9f9e74241d59eccfe7040bfdcbbceacb374eda397cc53a4197b59e4f6f380a91Virustotal results 1.41% 
2020-10-19n/aexe b2f38c537e8a3bf02ab16f4b1fc763b6cdb21115054a33600d80f67c02347af9Virustotal results 14.08%AveMariaRAT
2020-10-16n/aexe 02f843c7f39f2272ca48f70f9dac4f617a70ea246c81951287943b3ad890f9dan/aAZORult
2020-10-16n/aexe 46db525106701a4871ab4c890b7822426dfa9232002388f74fc504ac70626210Virustotal results 26.76%AZORult