URLhaus Database

You are currently viewing the URLhaus database entry for http://banderu.us/rdp.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1000821
URL: http://banderu.us/rdp.exe
URL Status:Offline
Host: banderu.us
Date added:2021-02-11 09:54:13 UTC
Last online:2021-03-14 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-02-11 09:56:03 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 month, 1 days, 5 hours, 8 minutes Bad (down since 2021-03-14 15:04:14 UTC)
Tags:exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-03-11n/aexe 0d523274d47c33bc7218dbd4e3c2bc8d9f35cd295cccb3051df6566b0c8aada6n/a 
2021-03-11n/aexe e5b77db3b489a8c955683cc64e4c71df03b0462e1d8661dbd70013b1770e81b0n/a 
2021-03-07n/aexe 33a19887efb64f91d54b93851e80467888ede4612c38a97fe3deaf1823d57558n/a 
2021-03-07n/aexe 319b37298276ff36ff0d4c765c793c1e737e6d273022da995214526fcf8bd16bn/a 
2021-03-05n/aexe 92e8f1946b355174717c6802fa1f9fac0d78b5b1acb6c41113fdd7d919222825n/a 
2021-03-05n/aexe c0fa85e30cc9a42cad4b8cc82b94044f7806e17fd07466e5355ea1e69de9a579n/a
2021-03-03n/aexe 6f48e101007a2c4c4c5c80ce39f697f2958107c12ccfbc3ad521a7195ecceadcn/a
2021-03-01n/aexe b0638f7b0304a3be813df68c557e90999820aa7018e279e88a19fff0c49f064an/a 
2021-02-28n/aexe bc1aabf9dcff06da88c69403a1f791757c4e93c910d48a14c76194dbc3f7e5b0n/a 
2021-02-26n/aexe 72fb1bfef6a4a8dd8e5104165ce1f5968602a3887ef4e7a1dcc13851cd2b6be1n/a 
2021-02-24n/aexe 01aa5a74d5069ad0023efb9ef27f181d6c268842111250254b5b812f4f93a678n/a
2021-02-19n/aexe cf5b509ae979c8ef242e36e999bfd4ab659f7ee75d777d41d14123022397c537n/a
2021-02-18n/aexe 3f153a33f49aac45ce9cd42137015b239f46afae4073340d3aad977877d9b965n/a
2021-02-16n/aexe a1d61a264f4e338c0f6fb4f98d58ae7bf573652dfb3bae779844a2c7bb34cd8fn/a
2021-02-16n/aexe b41864bcaa9443f1e9cf6457b3f6d7702fd7fa3fbdaae79e3033f2c82bb70a38n/a
2021-02-14n/aexe 41609e0f1ff71e0b6421e8e3bfbac0307c0f5f80f9e1b3b60de547a54a80de51n/a
2021-02-13n/aexe 772dab859fd099f0c1373b3fb4fec7aaca42ed71daabe1d1a413e3c66cc4f14dn/a
2021-02-11n/aexe a75b6f8ee56d8eaa809a7e7d265d9296f94524ddc2a1aac27284a7fb9947c915n/a 
2021-02-11n/aexe 8524ec166f99c15c47d3498db31df912b9f735ab341737421cf12032d00acaa7n/a