URLhaus Database

You are currently viewing the URLhaus database entry for http://kdsp.co.kr/room1/1.rar which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:163774
URL: http://kdsp.co.kr/room1/1.rar
URL Status:Offline
Host: kdsp.co.kr
Date added:2019-03-21 23:00:22 UTC
Last online:2020-08-13 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2019-03-21 23:02:04 UTC to noc{at}purplestones[dot]co[dot]kr)
Takedown time:1 year, 5 month, 0 days, 3 hours, 21 minutes Bad (down since 2020-08-13 02:24:03 UTC)
Tags:exe Gh0stRAT

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-24n/aexe ee2e75ded03f96470a11dd59fb5ae8beb5230ee061f40d7c2b222e6b93a0163bn/a 
2020-07-23n/aexe 4df7e20b15dc14dedae15e283b0c1f33f38866c1ce2abb1c16fcd36cf81896e8n/a 
2020-07-22n/aexe f6659c0455b86a77f59b4e44c17a23806690e5446dcda87d3408005cdd815f16n/a 
2020-07-22n/aexe 532eaf22a080fa6d4f5baaee75c31a304f16fb548e1f4cd1e9128d460df99153n/a 
2020-07-20n/aexe d97033e86edcace6e21b736432545ffa3ec756bbe1132fc9ee37609028d1a5f1n/a 
2020-03-31n/aexe 76807b15c0014db3490a3e19c1c7dc4f3e5c789767e96ad59c5d4c5f75af946en/a 
2020-03-30n/aexe 7a01f024a9d66368c99485d551c25593326dded650ab11214222717df36f68b1n/a 
2019-06-11n/aexe e8cc213a4f124fa3e93c636b2bf19001df4f20e678739886fbc4b5073438d0e1n/a 
2019-03-21n/aexe 3e8dd70c08a940466b486f393409fe74e3ec39c21ff60ddf6ffb1ee7a2511ed1Virustotal results 75.47%Gh0stRAT