URLhaus Database

You are currently viewing the URLhaus database entry for http://saba.ac.ug/ghjk.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1596394
URL: http://saba.ac.ug/ghjk.exe
URL Status:Offline
Host: saba.ac.ug
Date added:2021-09-06 08:09:29 UTC
Last online:2021-10-05 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-09-06 08:10:03 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:28 days, 23 hours, 56 minutes Bad (down since 2021-10-05 08:06:22 UTC)
Tags:32 ArkeiStealer link AZORult link exe RaccoonStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-03n/aexe 314afbf4a221c8ce6f8d2674277a3c2fb119c34222b5c3ed83afd79005e352f4n/aAZORult
2021-09-25n/aexe d3d844bca757cfac2bc5cd8cc9bd9d806358eb3af100fdecddb5d0848cd706afn/aArkeiStealer
2021-09-17n/aexe 2d7fcb87c1ac2786c319720a857328d19e7ac523396992b445fec60de47919dfVirustotal results 46.27% RaccoonStealer
2021-09-11n/aexe 42caa5a2e19134770914b3b33dffaceaae03a44fc52babd8abc250d7d7696945Virustotal results 62.32%AZORult
2021-09-06n/aexe b594ae37dfb90a402bda0803680b455ababcc67e1add26f3c3f8f192d97dbe2aVirustotal results 69.57%AZORult