URLhaus Database

You are currently viewing the URLhaus database entry for http://tuzlacastajanslari.bykmedya.com/soft.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1612715
URL: http://tuzlacastajanslari.bykmedya.com/soft.exe
URL Status:Offline
Host: tuzlacastajanslari.bykmedya.com
Date added:2021-09-12 05:31:12 UTC
Last online:2021-10-13 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-10-12 23:41:03 UTC to abuse{at}ni[dot]net[dot]tr)
Takedown time:3 months, 18 days, 8 hours, 33 minutes Bad (down since 2021-12-29 14:06:02 UTC)
Tags:32 exe RaccoonStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-01n/aexe eef1acad2ca540f1415d05a4e5d3b932cf7f59317717621a6687d6e83758413en/a 
2021-11-28n/aexe 0dc3de87d8518c682228248f93b1052e16c9e79021d426e42b6e36f1768133cen/a 
2021-09-12n/aexe 956e8d25aa50c8a739d438ee8fdee84263003fe7bf420bb2afb74d7649a410eaVirustotal results 30.77% 
2021-09-12n/aexe e1683aeee2b3ddd9b6265481bdf4c780d640a63ec9a5aca4077942c26cfd5502n/a RaccoonStealer
2021-09-12n/aexe 5bb789c348134d55a489d0c6fa248fa231a79a33c0ea5098acb10003363273f3Virustotal results 37.68%RaccoonStealer