URLhaus Database

You are currently viewing the URLhaus database entry for http://watchdogdns.duckdns.orgwatchdogdns.duckdns.org/mrd.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:92634
URL: http://watchdogdns.duckdns.orgwatchdogdns.duckdns.org/mrd.exe
URL Status:Offline
Host: watchdogdns.duckdns.orgwatchdogdns.duckdns.org
Date added:2018-12-11 02:30:17 UTC
Last online:2019-03-07 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2018-12-11 02:32:04 UTC to abuse{at}colocrossing[dot]com)
Takedown time:2 months, 26 days, 4 hours, 10 minutes Bad (down since 2019-03-07 06:42:08 UTC)
Tags:RevCodeRAT exe HawkEye link LimeRAT QuasarRAT link RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-03-05n/aexe 64af09e2e96a2b891dfcfbf9c81e25d16f14ff0986834318313b22dfa83f6574n/a 
2019-02-21n/aexe 27a3fc452725be3bbf5e82f96228b16bedd8747bbf5638c8277e7c76f07c857cVirustotal results 33.33% LimeRAT
2019-02-07n/aexe 110ef1bf1f55e400ef17c8179a25f696c4f667741b89a998ba0ea041fe53e916n/a RemcosRAT
2019-02-02n/aexe 672b504f3c51fe58144d664f757072a17877a0682e08b35b8e69b6721022768dn/a 
2019-01-29n/aexe 2c94e1ac0a94aa3aa6e03f9ff33eb0f94f916b00ca0a34a4da62d113c438327fn/a 
2019-01-26n/aexe e7056a38ead49cd247e653e500510e3c6d73898bd29cc629ef1262e68ef191bbn/a LimeRAT
2019-01-24n/aexe 9d6ade1d690124086d594c06ba8db497434c560fc7d9b4a8a4df12ffa441836fn/a LimeRAT
2019-01-23n/aexe ca37979ed84f2bc2cee74191df9f03ba9970d31a9d04654fd541ad073d706c6fn/a HawkEye
2019-01-20n/aexe a07c195912a35bb4f09c0adbc3e174e9dcf7bbb744c036f8e4698aaef44f0763n/a HawkEye
2019-01-17n/aexe 1a422b2a6288cbb50beb3c380df782bcccf7516e74fceb799d5e1b014e9fb252n/a 
2019-01-14n/aexe c69bb2d27769eba71d7b031249b8cac97c65f560dd1b06840fd2d6c2b3ce58b1n/a LimeRAT
2019-01-13n/aexe 987b518b7a461694585044a73f4121f88faf5ff4b6ab9575cbeb717f802fc606n/a RemcosRAT
2019-01-12n/aexe bb93d16760825fb1ef7127af898b6b1e0be7e9829d0bffae4b7c0d2bdec58101n/a LimeRAT
2019-01-11n/aexe 7156b8450ce9aa9f4b4e47972df99caa22b5ae87d0d88b5417be301ef4e09b19n/a 
2019-01-10n/aexe 2f31154a459e48c110a42c2cd1e13580d72569e93a1291c48160a8cdb6e44111n/a 
2019-01-09n/aexe 2ee2dc10a0d93a93bdb2c301acca3368ea311eef78eba5299f05a14d9e5867b4n/a 
2019-01-07n/aexe fd31089c7084acd50019b50d107eaa77999f52c16dcbee55f12544f1024ba8e8n/a  RevCodeRAT
2019-01-04n/aexe ccc59f7a7f97047cb768a15ee44e1af2d609764dc44195dd78c28c758b8629f8n/a 
2019-01-02n/aexe 3ec8523e399cc2c8603fb87e77695625f4c2c85db67ea3e2a630be2dcc18d248n/a 
2019-01-02n/aexe 77b4754b91d276916f63dfedd7b8d52cb93237fa08eca93bed7e2d02013a483en/a LimeRAT
2018-12-24n/aexe 851960ccd0f680682be12ac57ae6cf639a605163344be8c1f7dc16238d909dabn/a LimeRAT
2018-12-22n/aexe 8078741205658d4255dbb3d62ea353b2c4cb58b0a08053c1d85f3191fc1ad2dfn/a LimeRAT
2018-12-20n/aexe fdd871366ddf7d08ae6bebc663100483a0b3f02ac393f020d25e980c60070eecn/a  RevCodeRAT
2018-12-20n/aexe b358a99a1ece1007fd0d6f4269ddbf6e6cf04f31e53093f4cd0e43802cb5c251n/a LimeRAT
2018-12-18n/aexe ae43cc01ee0b8fbba682ae40f8e097ad1bad6bc465aca99064396bd1162b59fcn/a  RevCodeRAT
2018-12-17n/aexe cd541ee7b22487180ad5be07be2dbee4a0fb73392e9c43b07a0665e6d5cc5e28n/a QuasarRAT
2018-12-15n/aexe 6a327b0cf6e2816f8b9434770955cde3e3c57d91026c0753221ff81a80b4cfdfn/a  RevCodeRAT
2018-12-11n/aexe 34bbe865c813adccc3e9690ea8eb998eec414e509103d613a010576743bd858an/a 
2018-12-11n/aexe 1b3190bd9170d8a74c558e674de5d62bb868c4a6a4187a03055534d4e1f6834aVirustotal results 64.29%  RevCodeRAT