URLhaus Database

You are currently viewing the URLhaus database entry for http://abidpasha.com/lk.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1393107
URL: http://abidpasha.com/lk.exe
URL Status:Offline
Host: abidpasha.com
Date added:2021-06-24 00:52:13 UTC
Last online:2021-07-03 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-06-24 00:53:04 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:9 days, 10 hours, 1 minutes Bad (down since 2021-07-03 10:54:30 UTC)
Tags:32 bitrat link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-03n/aexe 442ba3c3f38aae2a9d3525f5bcd1e38949726b9f33d3ad48a4fb109784b7b394n/a BitRAT
2021-07-03n/aexe bf3c03c86e4c530a703b7afa798851d6e05cf7f7021f18581cf59f814610850en/a 
2021-07-01n/aexe 9a4407f9dab46013f44f33007023209be5aeb572d3499a92ea49f7ec10ff15a7n/aBitRAT
2021-06-29n/aexe f94522b7adb7ad83d04a493601f0b1c71d4d8237837bacbd6732bfb851a0e1b7n/a
2021-06-29n/aexe f30a85706bfa72f26a859b9ecdd674a580eb70d59536470ed03296cc8bb4a581n/a
2021-06-29n/aexe 1cf793904da9069334c04d61c3ab425f379f596b7dbb50c5ddc884de75d462ffn/a 
2021-06-27n/aexe 1ee7cca136cddd78f9fef1ce6cdeff4a50112e3158672c76aeadd7e6d0ef8e73n/a
2021-06-24n/aexe 3f3b3d25afd26aa1c4483f0437c192a7374f85bdcf0d52be8f4ba6bd63b09cd1Virustotal results 41.43%BitRAT