URLhaus Database

You are currently viewing the URLhaus database entry for http://hdgbcnuy73wjnho9jusrnhfhejfuy78wyi7jfknv.ydns.eu/CKC.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:752072
URL: http://hdgbcnuy73wjnho9jusrnhfhejfuy78wyi7jfknv.ydns.eu/CKC.exe
URL Status:Offline
Host: hdgbcnuy73wjnho9jusrnhfhejfuy78wyi7jfknv.ydns.eu
Date added:2020-10-26 14:57:04 UTC
Last online:2020-10-30 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-10-26 14:58:04 UTC to abuse{at}ovh[dot]net)
Takedown time:4 days, 5 hours, 51 minutes Bad (down since 2020-10-30 20:49:38 UTC)
Tags:exe MassLogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-28n/aexe 09793e9ccc95003ef64fe7d0a3417c04962ef3221b01fec9a1d8bf801a53251an/aMassLogger
2020-10-27n/aexe 49d9309eac532c0e556de20a5caab67bf0819266c5eee7aeb794472a3f70b3d6n/aMassLogger
2020-10-27n/aexe 2268c04275e6483759c53e8fc26f983591be004ac63afd19591da079bbf67875n/aMassLogger
2020-10-26n/aexe 3251a40b247e2a5428a63e66306667d8fb630f56b0b6d49afd05ed72adcdd731n/aMassLogger
2020-10-26n/aexe 8ea1d5e023c174a65c047ecf0f633ef66ba5adfd58ff0cc09ad084fd31f84278Virustotal results 28.81%MassLogger