URLhaus Database

You are currently viewing the URLhaus database entry for http://igynjkolwbnxvzaghuoplmnahuqwsbhyexbzmbdu.ydns.eu/CKC.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:780172
URL: http://igynjkolwbnxvzaghuoplmnahuqwsbhyexbzmbdu.ydns.eu/CKC.exe
URL Status:Offline
Host: igynjkolwbnxvzaghuoplmnahuqwsbhyexbzmbdu.ydns.eu
Date added:2020-11-02 18:02:06 UTC
Last online:2020-11-09 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-11-02 18:04:02 UTC to abuse{at}ovh[dot]net)
Takedown time:6 days, 21 hours, 18 minutes Bad (down since 2020-11-09 15:22:14 UTC)
Tags:AgentTesla link exe MassLogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-11-09n/aexe 985aeed489ef3a3af3b21b0adb1bc8a4e7d444522b742bfedee03da6879b7fc8Virustotal results 27.78%MassLogger
2020-11-05n/aexe 25290105f9496de7a4fcc5150511793c4300066ac2481bdc9dabf1d1f6f514bdn/a
2020-11-04n/aexe 2800f779fcf9eb82626c08e19c5c2a46a149a1a0d046ef79c6c9ac1a44c6017en/aAgentTesla
2020-11-04n/aexe fb5c8438c12b2a2fafeaedd0d328c2669d6c8ef6fed06455e630d1edf4d47651n/aAgentTesla
2020-11-03n/aexe b711fc441777905b534050ba32f04836a1a791dc4cfbf850b1ee7faecd6a82dan/aAgentTesla
2020-11-03n/aexe 1f68682f037b5964da035112cfcaac453d8a51ce7912128937e10f843de8dbacn/aAgentTesla
2020-11-02n/aexe 98e4f3e059c6a9bbae6734bbef5300db9f237bb45bed40280fd82f0592ccaedcVirustotal results 29.85% MassLogger