URLhaus Database

You are currently viewing the URLhaus database entry for http://topsient.com/ski.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1690810
URL: http://topsient.com/ski.exe
URL Status:Offline
Host: topsient.com
Date added:2021-10-18 11:33:06 UTC
Last online:2021-10-30 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-10-18 11:34:03 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:12 days, 3 hours, 10 minutes Bad (down since 2021-10-30 14:44:12 UTC)
Tags:AsyncRAT link AveMariaRAT link dcrat exe QuasarRAT link RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-29n/aexe 168f62c6ea11a386469563c360ee5517da31015e774ccc9c8ba3d1bd4b4f45efn/aAsyncRAT
2021-10-28n/aexe 51f4fd4b792fe850919ba26123a12a05c7d711f174243688cbba43ddc9c479fan/a DCRat
2021-10-25n/aexe b9419a890ae732f44b4bbde7167aa6e559e912f8d1d7fa52fb9a70233efae334n/a AveMariaRAT
2021-10-22n/aexe 05b6108362c6bf38f974b2467432551c76f9157cc8f769b761467a7d08d65e7an/a AveMariaRAT
2021-10-21n/aexe 30a556ecb048799fd3de548a040deabc6de900686ea7ed9c760e7090dfc1fc76n/a RemcosRAT
2021-10-20n/aexe f698c38ad9b7a96e28e7ab77e19d17f63c958ecb7c1fd755b27c7ef323355b75n/a 
2021-10-20n/aexe f65991084f00783d95ebf9db672ca60c2d734c9131e8bfd98fae6040b936fbd5n/a RemcosRAT
2021-10-19n/aexe 6b0ab733e35430a087bff4718cb7446be43dc8484a8669d887f717fd7cece0ebn/aRemcosRAT
2021-10-19n/aexe 66e8a14e6da21c74e44afd4ec991f7545c8d256490e3abc9fa4a982ba3ed3c4cn/a QuasarRAT
2021-10-18n/aexe 0b196e6b27ed15410bd946b1ccfd1de6b7af64a540cd0226b8eb9bd742d1b095Virustotal results 29.69%QuasarRAT