URLhaus Database

You are currently viewing the URLhaus database entry for http://180.214.238.186/core/ctf.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2239064
URL: http://180.214.238.186/core/ctf.exe
URL Status:Offline
Host: 180.214.238.186
Date added:2022-06-15 11:24:06 UTC
Last online:2022-07-13 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-06-15 11:25:07 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:27 days, 14 hours, 40 minutes Bad (down since 2022-07-13 02:05:26 UTC)
Tags:AsyncRAT link exe opendir rat SnakeKeylogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-28n/aexe d0c0e2a2f2fd47c15ed25abedbb58c289bfecdb3d5ae14c0c6f0ec9d4b348df4n/a 
2022-06-27n/aexe 68a485c9ca3a33afbf0d90f046ad77f2b4ac2845c8a8bd131e16a72580a7b693n/a 
2022-06-24n/aexe 77fc50e59287031c6d133db4018b2f1217eb32b80e8ee90832337d924bfd5b0bn/aAsyncRAT
2022-06-23n/aexe 8a9cefa63802b04de4ee53aa8b85fe4911eed878ef7d2eb207088a25f561a399n/aAsyncRAT
2022-06-22n/aexe 285279bec716ca903235cb35cefed0d292a9be4be95c6df5c9529cba61812935n/aSnakeKeylogger
2022-06-21n/aexe 375e3b9aca92cb15f9e872d6d8495b40bef87ebce8fb10a67d7e6e816da3c40fn/aSnakeKeylogger
2022-06-16n/aexe 33910338115a8da407e1a15477e593b07fc645ef619a787bbb51ee77906c6e4cn/aAsyncRAT
2022-06-16n/aexe 3b51dc9ecd141fd30a12ab8a0d4a10bb3b50ec28a80ee64cfc736ca8dd2ba7e2n/aAsyncRAT
2022-06-15n/aexe 3f140dbc69924c00d56b0797cd7cc50aceea1bf858bbadc05dab6f7ede11821cVirustotal results 44.12%AsyncRAT