URLhaus Database

You are currently viewing the URLhaus database entry for http://hgoz.12v.si/EXCEL.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1435773
URL: http://hgoz.12v.si/EXCEL.exe
URL Status:Offline
Host: hgoz.12v.si
Date added:2021-07-08 09:49:05 UTC
Last online:2021-07-26 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-07-08 09:50:04 UTC to abuse{at}serverion[dot]com)
Takedown time:18 days, 4 hours, 30 minutes Bad (down since 2021-07-26 14:20:39 UTC)
Tags:AveMariaRAT link exe RemcosRAT link SnakeKeylogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-21n/aexe 548f6a3cc2e79d94f8735680af5a91b4d8dc1a003e578d9027dca782939c9755n/aAveMariaRAT
2021-07-19n/aexe 2d1e7b0b691c806b94f685f348dbe5bb4857edf0408f363314fe97535f4723a1Virustotal results 26.47%AveMariaRAT
2021-07-15n/aexe 691c75376ade3956492197d79853cab8eb38dca6dc2a7c2be3d4f28f445a3d2bVirustotal results 26.09%AveMariaRAT
2021-07-14n/aexe 20abe25c4f02f73cdda3e8e74187202fbdbf5fa2fd7fe92b2d1ab328b66c1950n/aAveMariaRAT
2021-07-13n/aexe dd5107d7cc5b86ef5a650ea6e01b662066c34072859272fa886379e304e7df43n/aRemcosRAT
2021-07-13n/aexe 04cde0c2284cc4dc8f8a5aeadafca6819ab9d11dfb76fb7f3a2fbbf91d3c0e5dn/aAveMariaRAT
2021-07-13n/aexe 538b973f12e7eb9390b9b64cb36818b73b139bee73af7d5c7b8c5d72a0dc037aVirustotal results 31.88%AveMariaRAT
2021-07-12n/aexe 8c366ee263db756db2648d00eb615b16fc8b92262f8bdf7d3269267eb1382cb0Virustotal results 22.39%SnakeKeylogger
2021-07-11n/aexe e4ebcaef6d330f0a6eed54fd991ec6fcf996f210570da002c949c4400bd91e74n/aSnakeKeylogger
2021-07-10n/aexe 2c2ce93844f1742c83a36255e95c4eaa3ce0fb3162891968b22ee3dd46abee2aVirustotal results 26.47%SnakeKeylogger
2021-07-09n/aexe 4802b87ba7e4f7c1815d0c027aab96c0fcd74099ea8fdd236a9909e0ca00faf6n/aSnakeKeylogger
2021-07-09n/aexe f99002091475b0c5f423e2d9efe182de66019616c5fda6205efc3d9bd2f5ff45n/aSnakeKeylogger
2021-07-08n/aexe d5bf73c697fe079c68e107fa41cc97a328c6190507a8514a26376ef554659d9dVirustotal results 21.82%SnakeKeylogger