URLhaus Database

You are currently viewing the URLhaus database entry for http://ramalubegroup.ydns.eu/last/adik.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2266114
URL: http://ramalubegroup.ydns.eu/last/adik.exe
URL Status:Offline
Host: ramalubegroup.ydns.eu
Date added:2022-08-05 19:06:07 UTC
Last online:2022-08-19 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-08-05 19:07:12 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:13 days, 7 hours, 20 minutes Bad (down since 2022-08-19 02:28:09 UTC)
Tags:32 AsyncRAT link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-08-11n/aexe 588820a7535e7676d317a5a5fa05530deba4e7ad4501bb99234166992f9c3673n/aAsyncRAT
2022-08-10n/aexe 2613eced323aa97af1eec9eee826e07badefae366cc6988eba8cab98a965e605Virustotal results 32.39%AsyncRAT
2022-08-08n/aexe d76882be8d96e53f625b110158fd7e480dd2cabe8a49ffd8fedcdba1e910706an/aAsyncRAT
2022-08-08n/aexe 848fcb87c298f41af7286e75be0aeb88ddf92b38bf6d78e71228f8017b20bf78n/a AsyncRAT
2022-08-07n/aexe 0928b349df8f28bc571a023fd30922269e62e65257236e0275e0c3e863cb4e0en/a AsyncRAT
2022-08-05n/aexe da6abb6f3aae250d50ed09b6eacc267c33e50895e3ebd7e6ba800ab018351ec5Virustotal results 53.52%AsyncRAT