URLhaus Database

You are currently viewing the URLhaus database entry for http://ramalubegroup.ydns.eu/time/dub.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2266008
URL: http://ramalubegroup.ydns.eu/time/dub.exe
URL Status:Offline
Host: ramalubegroup.ydns.eu
Date added:2022-08-05 17:27:11 UTC
Last online:2022-08-19 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: AndreGironda
Abuse complaint sent (?): Yes (2022-08-05 17:28:06 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:13 days, 8 hours, 41 minutes Bad (down since 2022-08-19 02:09:15 UTC)
Tags:AsyncRAT link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-08-13n/aexe 49d302ec1c67763ebd77425fa8660d7f5840fdb1f146fce3982cf3d11500d12en/a AsyncRAT
2022-08-12n/aexe 5480fb14c3e1bce2eb3ac68f45a64d997aa6a7e33132280d31ea037f55d7e349n/aAsyncRAT
2022-08-12n/aexe 1ea9dafb36977806c0d479f0031a065b91fa80f9ce0dc8afc6553a7c9986b810Virustotal results 41.43%AsyncRAT
2022-08-11n/aexe 38e1bbae005365e92cf80aa6ef199d5107af57fde3afb02c31dc1bde875c68f7n/aAsyncRAT
2022-08-10n/aexe f6e1e1e20ad34b27e179b40beee6a329ccf287a70be4b786b738824f3d6d01f1n/aAsyncRAT
2022-08-10n/aexe 83e02d84ab9cb70a5c87e01a595ba780cb45629018dadef0e10d6ccb850f3aa5n/aAsyncRAT
2022-08-08n/aexe fa24d9f844937a49773272aa1d1661ad8f0f467310971bfc167a111c4cf6823fn/a AsyncRAT
2022-08-08n/aexe d7efd3e9d78cb66f8234be50f8ebf470c01a90aa4eaae7c1f99a2a716283380bn/a AsyncRAT
2022-08-07n/aexe 546eb85717e02b1d16df99eade200e4bca7464014f732f62c9c4d3885b1a2854n/aAsyncRAT
2022-08-05n/aexe 9d19de1d4be447775e3345eae357a9571bd86a607eaf25df48a6840acbc390ccVirustotal results 23.94%AsyncRAT