URLhaus Database

You are currently viewing the URLhaus database entry for http://ajibollc.publicvm.com/vic/ctf.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2181346
URL: http://ajibollc.publicvm.com/vic/ctf.exe
URL Status:Offline
Host: ajibollc.publicvm.com
Date added:2022-05-05 20:51:10 UTC
Last online:2022-06-01 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: c_APT_ure
Abuse complaint sent (?): Yes (2022-05-05 20:52:06 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:26 days, 5 hours, 17 minutes Bad (down since 2022-06-01 02:10:05 UTC)
Tags:2e25a30c76eb1348402a45e3a3b72c71 4138e3b835b27b900a5df89aecb7e760 AgentTesla link AsyncRAT link C2:185.19.85.136:6060

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-05-27n/aexe 76b74d5bca4b73e87a942aa32f535f4d50fd2d2b7b04c6a3a9703d7a5093518fn/a AgentTesla
2022-05-26n/aexe 5a4bfcf2c5e5793af21ee7eba81fa96c93f3cff7200880f6563658373c4cff2en/a AgentTesla
2022-05-25n/aexe e3206b5c08f64907c80f69e5702119d6fa57019366fcf3722ed06bab18c3dd5bn/aAsyncRAT
2022-05-24n/aexe 8b8749dd4fbb546524dbc10b4f9bec1a3f3a04c9712dfa6a804aa7aad2708c71n/aAsyncRAT
2022-05-24n/aexe b94554c24d16a785585c2403b9833a42648ca26bee861c524c05b1b69a614881n/a 
2022-05-20n/aexe 02c460bda27f5171c39df0fa18b8c103c0b9a5aed1a1a114b51e3b6758e77364n/a AgentTesla
2022-05-18n/aexe ab0e679ce2652c1c47476887178d88a0d307327dd4d6b6e35bdadff18aeea309n/a AsyncRAT
2022-05-18n/aexe 501ed0b54c04752bdca7b74ad87679ecbf5b14083bc1dad2a98e8980b980c40en/a 
2022-05-17n/aexe 840e52fa1cbf3b8f5a7f30ae986d18bb230419e9e50c4b34dea1edf97e1dabe4n/a AgentTesla
2022-05-17n/aexe f0e20dc64dbb6bf7cb2f71eb4a1f09b9d6b6c76e421e22906623b89a9a0cefe8n/a AsyncRAT
2022-05-16n/aexe 852b15cc9310439586f10b160ef91f8ad1d034aac3968a930205476dc474ea7bn/aAgentTesla
2022-05-14n/aexe f5ee7cd9737f914badddb5fc0ab117e10b586f27db6a0c724ab08b5e90acf87aVirustotal results 17.65% AgentTesla
2022-05-13n/aexe 007bd5c3b853dbc5ae38222268156e27865907105e9ad926d08bc2dc61e01096n/a AgentTesla
2022-05-12n/aexe ac5810d629f33b83eede0d3cabecb3d6b1c1f25ca26ff1d3151fdedcb85db44fn/a AgentTesla
2022-05-12n/aexe 3b7520be1315f77bc6d146f6617ab789e92893584d32b2d1148eda8537e0d1c7n/a AsyncRAT
2022-05-05n/aexe d70380869b6e15ff6788965d1569ce009c3e5e36f279fbd2052efb1c88e2faeaVirustotal results 35.48%AsyncRAT