URLhaus Database

You are currently viewing the URLhaus database entry for http://cracksmsa.ug/zxcvb.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1539152
URL: http://cracksmsa.ug/zxcvb.exe
URL Status:Offline
Host: cracksmsa.ug
Date added:2021-08-16 14:14:16 UTC
Last online:2023-06-02 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-06-01 09:27:06 UTC to support{at}zerohost[dot]io)
Takedown time:1 year, 10 month, 13 days, 10 hours, 47 minutes Bad (down since 2023-06-21 01:05:10 UTC)
Tags:32 ArkeiStealer link AZORult link exe RaccoonStealer link RecordBreaker link RemcosRAT link Rhadamanthys Vidar link zgRAT

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15n/aexe af97469272846b1111d2019f010fc7e9e8c6149777df1d09f7eaccbb031354e1n/a 
2023-06-12n/aexe 52bc1f7eb3b921bdd95ee2e00b42d3195d80c35c5002ade20f2df101b618715fn/a 
2023-06-12n/aexe 35ef5c3b4cee08c40298e6bc22320ffc48bb9e892cb1d44c0860ccfe187ed831n/a 
2023-06-01n/aexe 5d2e841645576d0eefcc6bcc6c0d480c0c6874f05a56e92441319a5c41b38979Virustotal results 68.12% AZORult
2023-05-03n/aexe 83263fa7b8c560ae026a24d6ea9e6eafb16aa207cc5557c65c7f71f703f3a593Virustotal results 44.93% 
2023-05-01n/aexe e99f79618b991de5d1052096950590a4fe833b885871a96bb1202e3d6dd876a0Virustotal results 55.07% 
2023-04-30n/aexe ff277e11345c79a60de0ba45011460629487e82e8b0b58a8ddfdfeca2d7623f5Virustotal results 45.07% 
2023-04-22n/aexe 0127ebf8628f963a453520b0149fc11fc5d0a56536ce2a41c9dfdd3c597a0746Virustotal results 23.19% zgRAT
2023-04-18n/aexe d9b498faf01b9eb598761915a6fc2fb4f1ab2317d354348baca6794730fd15d3Virustotal results 44.29%Vidar
2023-04-14n/aexe 0cff8404e73906f3a4932e145bf57fae7a0e66a7d7952416161a5d9bb9752fd8Virustotal results 41.43% Vidar
2023-04-07n/aexe 4130ce135fbfab00618f261a0397e88479d2f61e1ed0d09ebcde525439774f3en/a AZORult
2023-03-23n/aexe 60289bfd6a3a67726074cccced70f113419fea3b76c00855fb7dc5fa332d3f7aVirustotal results 33.33%Rhadamanthys
2023-03-16n/aexe a54493e71a7f28fe61e607ba4c089ada71e13ff9e1df6cef5619a4163e2b0a1fn/aAZORult
2023-03-14n/aexe 9647f0d41ffd3a4ac705a55358906fa7c6fc7d26b5068a18bce4da9c7af0300en/a 
2023-02-05n/aexe 4908e51e65bf67fdc3a559be7c47c3df1354a4a864b931cb176d282048f8d9c2n/aAZORult
2023-01-13n/aexe 8c5df030de0c79f2155a60e0d5f41889ec8d07d441279d406996dca4639f8539Virustotal results 32.86%RecordBreaker
2022-12-19n/aexe 746669c6be1807fdafbc7ee3f1e958e1b584fa31688742bcc044d269af94b0d8Virustotal results 61.97%RecordBreaker
2022-11-26n/aexe 9063dd7d69236cca3007587ccc04334b4289ec456f6983673f3d9f749092a29cn/aRecordBreaker
2022-10-28n/aexe 7fb0ba02228819f3f3774286d387cd02fae09fca7e6a0e456f92d1704f67e2a5n/a
2022-10-06n/aexe d4227ec9dd2159223342099e0ed7d55c0691fe677ab2fc513c149a137e50ced8n/aAZORult
2022-10-01n/aexe 9a81a9c84d36a49be8286458ce7c919538647711b28fedae9b5521762ff76030Virustotal results 40.00% 
2022-09-16n/aexe e553b05dd2afafadb6ad38d3463056e50cfa31ba3ac5489a7a114ec35ef10194n/aRecordBreaker
2022-08-19n/aexe 65020d58d04109f2e8f46d12e43aeee9e98ec182db4bd4a2b2c336978e696c06Virustotal results 52.11%AZORult
2022-08-14n/aexe ea34b776b896df9512f0aab37e3b0d56ff012a0906910a957db335f9e7dcf2d4n/a RecordBreaker
2022-07-10n/aexe d75d7b0534ff648f16f5751be79a2c23158b6412a780180aec78c77c7e95071dn/aAZORult
2022-06-25n/aexe 6887d3d4d5baa135418c2305915c56b448960d03c427f6c63c430465ddaa6547n/a RemcosRAT
2022-06-20n/aexe 2ced9b36b931b73b1d325bececd01f0e4fa6bd0fff98f8b76f2f45b473311cd0Virustotal results 51.47%AZORult
2021-10-03n/aexe 394c61c695af669dcfe4d3dcf73de5099ed8e7fea036dd25f45ff6d234f9547an/aArkeiStealer
2021-09-25n/aexe 3ef65642968377f832f577a3631fac424e24e3c86ead5539d31b0583ddd69de3n/a RaccoonStealer
2021-09-17n/aexe e80d7de90473de5e1d9fb140d2537896872f7a7ca665e9342514426604f4f708Virustotal results 20.90%RaccoonStealer
2021-09-11n/aexe 7b8ffb495d71939d9dfb9b4f4b0bd9bd9d3fad675aa487e2b20129c33f877c50n/aArkeiStealer
2021-09-02n/aexe 93ddf61c1aa7c0b867ffbd579b9febdeed4b027d14f8b86d62f7da493706731cVirustotal results 22.39%AZORult
2021-08-19n/aexe d0b7a458e09fd14ae8476200bd5acf2fc93ea0e2fea357079a88df80e720c23dVirustotal results 23.19%AZORult
2021-08-18n/aexe e8e31ad00eb7d6e4124e0d9dcd2a2e4ca20afa68007c0e655ae8cc5ca4bfdad9Virustotal results 23.53%AZORult
2021-08-16n/aexe 7045ebc8901b28437b116f9ff37d6e16caf2b47e3b7986cc233add8410f1ec9fVirustotal results 21.74%RaccoonStealer