URLhaus Database

You are currently viewing the URLhaus database entry for http://scientific.pk/ghjkl.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2271067
URL: http://scientific.pk/ghjkl.exe
URL Status:Offline
Host: scientific.pk
Date added:2022-08-10 09:37:05 UTC
Last online:2023-11-12 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2023-11-12 14:34:05 UTC to petr196721{at}yandex[dot]ru)
Takedown time:1 year, 8 month, 14 days, 0 hours, 23 minutes Bad (down since 2024-04-15 10:01:32 UTC)
Tags:AZORult link CoinMiner RecordBreaker link Rhadamanthys Vidar link zgRAT

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-03-27n/aexe 432747c04ab478a654328867d7ca806b52fedf1572c74712fa8b7c0edb71df67Virustotal results 29.17%CoinMiner
2024-03-20n/aexe 95cebaeaefaf1e9bc682b529e294bc169edced79c24184fa5b3750d5086876a5n/a 
2024-03-18n/aexe c7e3cb1d73f47d4215aea380df6a24021acd421915bcdbaebde8f15b7e381477n/a 
2024-03-18n/aexe 4dc4a5731364b47800189b82f0fe51fa1bda5ea828af59b57f22c88b7b13894eVirustotal results 42.47% 
2024-03-16n/aexe 03cc378fe9ae65ce1ee9b945bae86400b0256a103dda5b6c95ee0225d872b9c4n/a 
2024-03-16n/aexe 929216a1fb9248b5d815b400d55def58a052ff973ae83b83b7f620988d06e34fn/a 
2024-01-30n/aexe 217fbf967c95d1359314fcd53ae8d04489eb3c7bdc1f22110d5a8a476d1fc92en/a Rhadamanthys
2023-12-04n/aexe 189051c29319fac6a96fefc8158f9d27d61a55b668f3c8e3610a48617649518fVirustotal results 48.61%zgRAT
2023-11-12n/aexe ad7af6aca0ba3d2fe9adb3f391800420800c0f6aa00db064fc1292232a6d881eVirustotal results 40.28%zgRAT
2023-10-26n/aexe 8868ea6af3214fc758c93c1cb909231a76e22e718a4917aae5f2a60cf12af094n/aAZORult
2023-10-15n/aexe 22224f65c07515b2f61e29f7f1a14005d0de54378aa925d9e017bb2ac26b5395Virustotal results 41.67%zgRAT
2023-10-04n/aexe 77bfa9410910904d05a73ad3d6c28c1aa02b9d2ec82419f73600615b8b27f9a2Virustotal results 40.28% Rhadamanthys
2023-08-16n/aexe 4908195a2939cdd5b343f921824eb92757f1588f0b18610e10667e70d0892b90n/a
2023-08-07n/aexe 29f5a8629986da0b4a353e5423fb39c505cba7c06e7aa4b5a4029c5a1669ae95n/aRhadamanthys
2023-07-19n/aexe bcf3266e8996bcdb7acb686034f264b07c228ce37f1212b663b636cc0317ee1aVirustotal results 26.76% AZORult
2023-07-14n/aexe 83dfe9633679f8230ec3c00602388ce0c097ea9341263672da3decc0f782bb6en/a
2023-06-25n/aexe fc6ddb1f7644597b84d14e3efa4cd1a1d1ad0083141b3fa2a613cd3c092f6505Virustotal results 33.80%Rhadamanthys
2023-06-20n/aexe 680fefdbe11a969bd5c2189ec8fbdd7e60713592af516557bc5e62585766cdc7n/a 
2023-06-17n/aexe 2781134dad8985c1a667f0a9662439d0d8827098cb78623227d855efd4e9486fn/a 
2023-06-10n/aexe a030e37e4e9b939c3d65e459bb97f7f52c6917b3bf78a5b868e99fa8c98c2bcfn/a 
2023-06-04n/aexe fa01583a93b5affe2a576bcb547efa342bacaff6a79738ce1e35409569136ae6n/a 
2023-05-28n/aexe 5d2e841645576d0eefcc6bcc6c0d480c0c6874f05a56e92441319a5c41b38979Virustotal results 35.21% AZORult
2023-05-12n/aexe bf1d731a91e424fd67778f176ac652fa5ca39f2ab188ef740184e4b2808c7b3cn/aAZORult
2023-05-11n/aexe 79a7c9d15971c14d78baccbf211b3ca1e9adcb0befc6d3d1c5d92902d70678e2Virustotal results 45.59%AZORult
2023-05-08n/aexe 84c18f78f11b9bc3fd3e96925d2a7b76ab5ecfb927c377ad27456e191815b24an/aCoinMiner
2023-05-03n/aexe 83263fa7b8c560ae026a24d6ea9e6eafb16aa207cc5557c65c7f71f703f3a593Virustotal results 44.93% 
2023-05-01n/aexe e99f79618b991de5d1052096950590a4fe833b885871a96bb1202e3d6dd876a0Virustotal results 55.07% 
2023-04-30n/aexe ff277e11345c79a60de0ba45011460629487e82e8b0b58a8ddfdfeca2d7623f5n/a 
2023-04-22n/aexe 0127ebf8628f963a453520b0149fc11fc5d0a56536ce2a41c9dfdd3c597a0746Virustotal results 23.19% zgRAT
2023-04-18n/aexe d9b498faf01b9eb598761915a6fc2fb4f1ab2317d354348baca6794730fd15d3Virustotal results 44.29%Vidar
2023-04-14n/aexe 0cff8404e73906f3a4932e145bf57fae7a0e66a7d7952416161a5d9bb9752fd8Virustotal results 41.43% Vidar
2023-04-07n/aexe 4130ce135fbfab00618f261a0397e88479d2f61e1ed0d09ebcde525439774f3eVirustotal results 37.88% AZORult
2023-03-31n/aexe d9a2ded488ead1b53affcaa74dcf04b3b9385811eddfab2e68f545e305b63687n/a 
2023-03-23n/aexe 60289bfd6a3a67726074cccced70f113419fea3b76c00855fb7dc5fa332d3f7aVirustotal results 33.33%Rhadamanthys
2023-03-16n/aexe a54493e71a7f28fe61e607ba4c089ada71e13ff9e1df6cef5619a4163e2b0a1fVirustotal results 30.43%AZORult
2023-02-05n/aexe 4908e51e65bf67fdc3a559be7c47c3df1354a4a864b931cb176d282048f8d9c2n/aAZORult
2023-01-13n/aexe 8c5df030de0c79f2155a60e0d5f41889ec8d07d441279d406996dca4639f8539Virustotal results 32.86%RecordBreaker
2022-12-19n/aexe 746669c6be1807fdafbc7ee3f1e958e1b584fa31688742bcc044d269af94b0d8Virustotal results 61.97%RecordBreaker
2022-11-26n/aexe 9063dd7d69236cca3007587ccc04334b4289ec456f6983673f3d9f749092a29cVirustotal results 38.03%RecordBreaker
2022-10-06n/aexe d4227ec9dd2159223342099e0ed7d55c0691fe677ab2fc513c149a137e50ced8n/aAZORult
2022-10-01n/aexe 9a81a9c84d36a49be8286458ce7c919538647711b28fedae9b5521762ff76030Virustotal results 40.00% 
2022-09-16n/aexe e553b05dd2afafadb6ad38d3463056e50cfa31ba3ac5489a7a114ec35ef10194n/aRecordBreaker
2022-08-18n/aexe 65020d58d04109f2e8f46d12e43aeee9e98ec182db4bd4a2b2c336978e696c06Virustotal results 52.11%AZORult
2022-08-14n/aexe ea34b776b896df9512f0aab37e3b0d56ff012a0906910a957db335f9e7dcf2d4n/a RecordBreaker
2022-08-10n/aexe d75d7b0534ff648f16f5751be79a2c23158b6412a780180aec78c77c7e95071dVirustotal results 84.51%AZORult