URLhaus Database

You are currently viewing the URLhaus database entry for http://103.156.91.97/recent/ctf.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2266108
URL: http://103.156.91.97/recent/ctf.exe
URL Status:Offline
Host: 103.156.91.97
Date added:2022-08-05 19:05:07 UTC
Last online:2022-08-19 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-08-05 19:06:06 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:13 days, 7 hours, 9 minutes Bad (down since 2022-08-19 02:15:37 UTC)
Tags:32 AsyncRAT link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-08-12n/aexe ebc345d1416bab9c401e6c380199ca32accb0aaed66d5327aa2694284757aebfn/aAsyncRAT
2022-08-11n/aexe 88ce6b04f64de275ec9cfc98f50effcaa90aac02a6ff2a0802038aa39e40b7f0n/a AsyncRAT
2022-08-11n/aexe 53949b99b9556d09fe8d11ec6d41d96055a9fbf2a31360f38ab18b26b6511219n/aAsyncRAT
2022-08-10n/aexe efba734e54ef2c24ef4e8dbb5adc966af3b20b42ac7a43be04963c23297f9986n/aAsyncRAT
2022-08-10n/aexe 4311e14e2db7fe3ad8eb569fd2b5db6ee024474f1018962c9d64866e6942855fn/aAsyncRAT
2022-08-09n/aexe d56ce1bc69007aae6176c39ae79137f5b7013a7e4e4fdfce9457d945b92204faVirustotal results 39.44%AsyncRAT
2022-08-08n/aexe 02c71d1d645ca94afbcada9f86a032444503b89e5f72ed3425a0ba84f45b352cn/aAsyncRAT
2022-08-07n/aexe 634646caa5124c31a7c686be59e10a0c7dbc3e747bfac70596b4b024c2c362c9n/a AsyncRAT
2022-08-05n/aexe 52037b1dc98944493fc6ac41ab7fbc62c7eef79238c2b7f8d9242284e08f8a3bVirustotal results 45.59%AsyncRAT