URLhaus Database

You are currently viewing the URLhaus database entry for http://russk21.icu/autosqli.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2203988
URL: http://russk21.icu/autosqli.exe
URL Status:Offline
Host: russk21.icu
Date added:2022-05-20 12:29:05 UTC
Last online:2022-06-04 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-06-02 19:37:07 UTC to abuse{at}gorizontllc[dot]msk[dot]ru)
Takedown time:28 days, 9 hours, 57 minutes Bad (down since 2022-06-17 22:28:04 UTC)
Tags:exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-05n/aexe 880122544a0eac1adb8fde0bab910123d4399631b8a0ad78d8cf78e088980547n/a
2022-06-05n/aexe 8b3ae2c1e6349c4bc29e61aef103f540fc18b76495ee0328c85efb8ddf5bfd62n/a 
2022-06-04n/aexe 75d8d919c47b24b3fdd61006b3bc546af3cfbafe618ebd2f8848aec289b5c7a7n/a 
2022-06-04n/aexe a084c540c0f847784592d7834f600299bb48c7ecaf948bf4f7897bcab8ead657n/a 
2022-06-03n/aexe 1acba777a2fc67f53f56ddead631b9dd23bab2cbcca1c991b2553f413dc9eb42n/a 
2022-06-03n/aexe 5b8ec10e01e2a4ac5d5e86454b176f78081f3f2717d8ae0a7d757b851a4d2613n/a 
2022-05-26n/aexe 2c24172c94ed3259430d2bbb2c3eaaf866e08274ec484782e79990e085a7966bVirustotal results 33.33% 
2022-05-20n/aexe 0b848654c8ea5a8d75b4c881c84df31cf856fa212c032452e74ccc906b9367e1Virustotal results 40.58%