URLhaus Database

You are currently viewing the URLhaus database entry for http://avira.ydns.eu/EXCEL.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1649284
URL: http://avira.ydns.eu/EXCEL.exe
URL Status:Offline
Host: avira.ydns.eu
Date added:2021-09-30 15:29:07 UTC
Last online:2021-11-01 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-10-25 09:22:03 UTC to abuse{at}colocrossing[dot]com)
Takedown time:1 month, 15 days, 23 hours, 39 minutes Bad (down since 2021-11-15 15:10:05 UTC)
Tags:exe RedLineStealer link Xpertrat

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-25n/aexe 36e7deadeeb8b242b2cdbf3b561899ed1ac51bbdbc194ab046ae961c76e0086an/aXpertRAT
2021-10-18n/aexe 9eea9caa338a673c1d88240839b08fe021ff9264620e7935ba5cb5bd3d00ebf6n/aXpertRAT
2021-10-14n/aexe f2926aaea4603961e15c9ac92eb599ddd51bd6e19bd7fded285a1db16753db87n/aXpertRAT
2021-10-13n/aexe 259dbea8ad36ca1f502f7eba9257bf7111313f4ef76c34922cd34dd5808b5181n/aXpertRAT
2021-10-11n/aexe bd5c24761ed0f7e6b1741abc9812e18794dd98524a7f4d3a8998d9a71af071adn/aXpertRAT
2021-10-07n/aexe 3e77ec2e0bbc394a1841bfb8f9b004f93fcbc35b401580abd01c92c41b6635aan/aXpertRAT
2021-10-06n/aexe 1a55b87ef779fe996b8aef3e98ea9252a5ce3a02d3a0a87000554bd41033a215n/aXpertRAT
2021-10-04n/aexe 9bd273556358606717f3d0e7d4a2521dba396d6838d8dfccb78bfc5c98590b84n/aXpertRAT
2021-10-04n/aexe 5bdc764598795f4afcb70f6ff95f29114f61ea24a1d836838125c08268e13de9n/aXpertRAT
2021-10-01n/aexe 9443d3d69b5e62fb2c944c1bc14b4d4ad21f3e0c70826b0d800e09eb9fb82d3fn/a RedLineStealer
2021-09-30n/aexe c830683f700f311fe3d533d849cf045b1cbed5ff76debaa6c3dd8f71c0daa535Virustotal results 27.27%XpertRAT