URLhaus Database

You are currently viewing the URLhaus database entry for http://kqz.ugo.si/powerpoint.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1442252
URL: http://kqz.ugo.si/powerpoint.exe
URL Status:Offline
Host: kqz.ugo.si
Date added:2021-07-10 22:09:06 UTC
Last online:2021-07-26 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-07-10 22:10:05 UTC to abuse{at}serverion[dot]com)
Takedown time:15 days, 16 hours, 12 minutes Bad (down since 2021-07-26 14:22:22 UTC)
Tags:32 AgentTesla link AveMariaRAT link exe RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-21n/aexe 548f6a3cc2e79d94f8735680af5a91b4d8dc1a003e578d9027dca782939c9755n/aAveMariaRAT
2021-07-19n/aexe cceb66dfe8d4e74b4f6ea988cb978e0438f29ffdb0923d7cb0590583fd31c46fn/aAgentTesla
2021-07-15n/aexe 691c75376ade3956492197d79853cab8eb38dca6dc2a7c2be3d4f28f445a3d2bVirustotal results 26.09%AveMariaRAT
2021-07-14n/aexe 20abe25c4f02f73cdda3e8e74187202fbdbf5fa2fd7fe92b2d1ab328b66c1950n/aAveMariaRAT
2021-07-13n/aexe dd5107d7cc5b86ef5a650ea6e01b662066c34072859272fa886379e304e7df43n/aRemcosRAT
2021-07-13n/aexe 04cde0c2284cc4dc8f8a5aeadafca6819ab9d11dfb76fb7f3a2fbbf91d3c0e5dn/aAveMariaRAT
2021-07-13n/aexe b5e245259b5bad5226aa4f388db61b2709866d6722ffd69f283abd3ca6851823Virustotal results 34.78%Heodo
2021-07-12n/aexe d74d5c42926dda1fa4499cd087c9058411dbf34831cabb822d512b2c9a3728a5Virustotal results 25.00%RemcosRAT
2021-07-10n/aexe ed62eff9a728c54286e8a6ed5b4bae53667496f354118a75a15a050e15a9df30Virustotal results 25.37%RemcosRAT