URLhaus Database

You are currently viewing the URLhaus database entry for http://russk21.icu/AScan.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2226855
URL: http://russk21.icu/AScan.exe
URL Status:Offline
Host: russk21.icu
Date added:2022-06-06 06:12:04 UTC
Last online:2022-07-08 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-07-07 21:42:04 UTC to abuse{at}gorizontllc[dot]msk[dot]ru)
Takedown time:1 month, 15 days, 2 hours, 43 minutes Bad (down since 2022-07-21 08:56:46 UTC)
Tags:32 exe XFilesStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-07-07n/aexe 85eb988ee7a039621da5bf44432b9c472836092fabb94e675b32890bf9c06d4en/a XFilesStealer
2022-06-18n/aexe b24bcecff3bf317920baac78f94c18dd3452a9f40eabf3ea57493365653b2dben/a 
2022-06-18n/aexe bbd14055793976d6fbc8792739ae3725b80df2536a88efdbbbdf3813a2ba972an/a 
2022-06-17n/aexe 3082581dfca1f8d01b1ad4bdad74c12893ca9baeecb915d4ba70d14caf81c27cn/a 
2022-06-17n/aexe 6c4a14186bd50f8935687f60a2bfac4c6512a26f6766923ef1d816a59c1d020an/a 
2022-06-16n/aexe 9c96bad250333fd0da7c708bf36dc1d9bb93fcdf418325bf5cf7299aeb9bcb2en/a 
2022-06-15n/aexe 2c5f9bc36f81b076c3db6aaff6feeb1fa969d31c701e1ae6365e18ae014f453cn/a 
2022-06-10n/aexe 97816e9d1588aa0d55ca3a7de289c54a813ee9c2dfc01d7f14431697f5b4101dn/a 
2022-06-06n/aexe d49cb57411da2fedea6b7e89b083282afa86342d97e9b31aa5ec58e6f9f01618Virustotal results 31.34%