URLhaus Database

You are currently viewing the URLhaus database entry for http://windarm.xyz/download/pl_installer.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1464583
URL: http://windarm.xyz/download/pl_installer.exe
URL Status:Offline
Host: windarm.xyz
Date added:2021-07-18 21:22:04 UTC
Last online:2021-07-19 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: benkow_
Abuse complaint sent (?): Yes (2021-07-18 21:23:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:6 hours, 24 minutes Good (down since 2021-07-19 03:47:58 UTC)
Tags:exe Raccoon link RaccoonStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-19n/aexe 9767a7bc59eb352854aa19905169dbd0801d99831322b0d899b58085509700ffn/aRaccoonStealer
2021-07-19n/aexe b1ba2d7a4b78729cf332357c9d5e5e63b51796bc107fff6a45dd6149a3760365n/aRaccoonStealer
2021-07-18n/aexe 137cc549003d220137e5277e1bd6ad842f212aa545d4ee7e58ad8b5c4e244cacn/aRaccoonStealer
2021-07-18n/aexe f6a03d67c52f6d431a7500e311b09edc8835d0cae6414e09b884fdab6e608e2bn/aRaccoonStealer
2021-07-18n/aexe 12fe2d127b9b07cbb83148502c9e297825fcd43c4538097e6ed376d31c020a2dn/aRaccoonStealer