URLhaus Database

You are currently viewing the URLhaus database entry for http://kqz.ugo.si/svchost.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1430903
URL: http://kqz.ugo.si/svchost.exe
URL Status:Offline
Host: kqz.ugo.si
Date added:2021-07-06 12:38:06 UTC
Last online:2021-07-26 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: vxvault
Abuse complaint sent (?): Yes (2021-07-06 12:39:04 UTC to abuse{at}serverion[dot]com)
Takedown time:20 days, 1 hours, 46 minutes Bad (down since 2021-07-26 14:25:21 UTC)
Tags:AveMariaRAT link exe Neshta RemcosRAT link Xpertrat

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-26n/aexe 885e34ff7befbdcdb027a017843cbacdba7eebb34d3df2e3113cceb9adafe8b5n/aRemcosRAT
2021-07-21n/aexe 548f6a3cc2e79d94f8735680af5a91b4d8dc1a003e578d9027dca782939c9755n/aAveMariaRAT
2021-07-21n/aexe c86c48057e9be95681c1a2d37f41232a2951988baa71fd415a03ba59725716b1Virustotal results 21.74%AveMariaRAT
2021-07-19n/aexe 2d1e7b0b691c806b94f685f348dbe5bb4857edf0408f363314fe97535f4723a1Virustotal results 26.47%AveMariaRAT
2021-07-16n/aexe 401bce69b94fd198482a5e4c760570afd0e6b85e64871894a4796acd5aeedd48n/aAveMariaRAT
2021-07-15n/aexe 691c75376ade3956492197d79853cab8eb38dca6dc2a7c2be3d4f28f445a3d2bn/aAveMariaRAT
2021-07-14n/aexe 20abe25c4f02f73cdda3e8e74187202fbdbf5fa2fd7fe92b2d1ab328b66c1950n/aAveMariaRAT
2021-07-13n/aexe dd5107d7cc5b86ef5a650ea6e01b662066c34072859272fa886379e304e7df43n/aRemcosRAT
2021-07-13n/aexe 04cde0c2284cc4dc8f8a5aeadafca6819ab9d11dfb76fb7f3a2fbbf91d3c0e5dn/aAveMariaRAT
2021-07-13n/aexe 538b973f12e7eb9390b9b64cb36818b73b139bee73af7d5c7b8c5d72a0dc037aVirustotal results 31.88%AveMariaRAT
2021-07-12n/aexe 99f6194509980cce34f244d9dbca6d6931f47a02361db73e0f2fc1fa103c997bVirustotal results 23.53%AveMariaRAT
2021-07-11n/aexe 27c7c159ac96bd76fc993fd76e2ee88106631af414a235a2a1aae1e31100af99Virustotal results 27.94%AveMariaRAT
2021-07-10n/aexe 86214e9a4b21afd0a46c93ee39eb99b188e43cc773a15f632fe8bea3169ee0a5Virustotal results 24.24%XpertRAT
2021-07-09n/aexe 6b22261ef9a97fde0923ffe05c7aa8317fd3b0e27c10fbc967f9961a5f39c105n/aXpertRAT
2021-07-09n/aexe 70707206bfdc0b86a9494f7780c55829e993a93a7d65d0279bc9c73b97ffc005n/aNeshta
2021-07-08n/aexe a89bc5bfb93026e56434c1354508dfa0a66821d35f522429582067fc7f9200ccn/aNeshta
2021-07-06n/aexe 142707e908e3691c05fe907738e9e0740a81be17f6a5a04d6e51647cdd57ba2fn/a Neshta
2021-07-06n/aexe 3fa53f6f68e280013eb9651a53a3c40a16fa99f7689d0761b3f95b2de68b22cfn/aNeshta