URLhaus Database

You are currently viewing the URLhaus database entry for http://fxqy.my.to/EXCEL.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1431625
URL: http://fxqy.my.to/EXCEL.exe
URL Status:Offline
Host: fxqy.my.to
Date added:2021-07-06 19:12:04 UTC
Last online:2021-07-14 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-07-06 19:13:02 UTC to abuse{at}serverion[dot]com)
Takedown time:7 days, 16 hours, 30 minutes Bad (down since 2021-07-14 11:43:23 UTC)
Tags:32 AveMariaRAT link exe RemcosRAT link SnakeKeylogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-14n/aexe 20abe25c4f02f73cdda3e8e74187202fbdbf5fa2fd7fe92b2d1ab328b66c1950n/aAveMariaRAT
2021-07-13n/aexe dd5107d7cc5b86ef5a650ea6e01b662066c34072859272fa886379e304e7df43n/aRemcosRAT
2021-07-13n/aexe 04cde0c2284cc4dc8f8a5aeadafca6819ab9d11dfb76fb7f3a2fbbf91d3c0e5dn/aAveMariaRAT
2021-07-13n/aexe 538b973f12e7eb9390b9b64cb36818b73b139bee73af7d5c7b8c5d72a0dc037aVirustotal results 31.88%AveMariaRAT
2021-07-12n/aexe 8c366ee263db756db2648d00eb615b16fc8b92262f8bdf7d3269267eb1382cb0Virustotal results 22.39%SnakeKeylogger
2021-07-11n/aexe 2c2ce93844f1742c83a36255e95c4eaa3ce0fb3162891968b22ee3dd46abee2aVirustotal results 26.47%SnakeKeylogger
2021-07-09n/aexe 4802b87ba7e4f7c1815d0c027aab96c0fcd74099ea8fdd236a9909e0ca00faf6n/aSnakeKeylogger
2021-07-09n/aexe f99002091475b0c5f423e2d9efe182de66019616c5fda6205efc3d9bd2f5ff45n/aSnakeKeylogger
2021-07-08n/aexe d5bf73c697fe079c68e107fa41cc97a328c6190507a8514a26376ef554659d9dn/aSnakeKeylogger
2021-07-06n/aexe 71d43dd5594e4d74bc9c4e79f13089f1f8938831f8155c49025d634cb9ab2423Virustotal results 24.24%SnakeKeylogger