URLhaus Database

You are currently viewing the URLhaus database entry for http://linkmifi.duckdns.org/file/net.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:925906
URL: http://linkmifi.duckdns.org/file/net.exe
URL Status:Offline
Host: linkmifi.duckdns.org
Date added:2020-12-17 16:50:18 UTC
Last online:2020-12-22 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2020-12-17 16:52:05 UTC to keith{at}fastlink[dot]net)
Takedown time:4 days, 22 hours, 58 minutes Bad (down since 2020-12-22 15:50:58 UTC)
Tags:AgentTesla link AZORult link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-22n/aexe d2be42441b0a5e46e566cc099ac90cef3e6cf121ba0ecec5bd6510264524c3e2n/aAgentTesla
2020-12-22n/aexe 09cfbae308d3cbdf17c9c71920feee15faac8ae3c78cf70d88fffbe49e166f4en/aAZORult
2020-12-22n/aexe 8abbd310dd3e242c31380c26ea16e9ac6380ac3cf53ad94fa368a70fa419abbfn/aAZORult
2020-12-18n/aexe 197137c5fd8c8051516f3004db4721d5d066b68d5d02695390a7e820635056acn/aAZORult
2020-12-18n/aexe 5a22e0da88853bf15c3062bce4c9cdaec4daf94d26dffb372f14c8641b519f24n/aAgentTesla
2020-12-17n/aexe 98ad8528238c8ab87e33bc9048ad95f06b9bc92b2e45b2ccbf49562074c56662n/aAgentTesla
2020-12-17n/aexe 67670c27b8182dc39f69b38b567ec82317754a2e1411285b31a8871640c62430n/aAgentTesla
2020-12-17n/aexe c63d4581dbe839bdb9865bcb6033e9e0ef459d1c5406e9f4fd3a05f48b46d0f1n/aAZORult