URLhaus Database

You are currently viewing the URLhaus database entry for http://nicoslag.ru/asdfg.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:228306
URL: http://nicoslag.ru/asdfg.exe
URL Status:Offline
Host: nicoslag.ru
Date added:2019-08-31 09:03:04 UTC
Last online:2019-09-18 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2019-08-31 09:04:02 UTC to abuse{at}alibaba-inc[dot]com,intl-abuse{at}list[dot]alibaba-inc[dot]com)
Takedown time:18 days, 4 hours, 30 minutes Bad (down since 2019-09-18 13:34:59 UTC)
Tags:AZORult link exe NetWire link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-09-18n/aexe 17ffdbd35b562dbef82fcc2dc68b947ae85d5595a40b6ddd47035bfab18094b6n/a 
2019-09-17n/aexe 1f5085a36c7abbfe642aeab26a6212b9e8d67c8843cca64b309b2ea3005c011dn/a 
2019-09-16n/aexe 4e51d11f159ccd329ee72f1f4dc1caebc3fcdf0e45e7be1e9ecfb73e21affa80n/a 
2019-09-14n/aexe c942a025d5e6cdc5051f45a89c483c100a5fcfd01b7a43fccf62148c4a4eac8fn/a 
2019-09-13n/aexe 896ff9878efd922fcfdff774a130373b84e90193fc483d48955b58886f367500n/a NetWire
2019-09-12n/aexe 11a22234d884590d3fe678cc1844f9b1b3c9f71562d79af914ae0963b53ba81bn/a 
2019-09-11n/aexe 6e3360bcd7d3087b3b91e12e3d579791183c62a4a080448b44150a16a301d3aan/a NetWire
2019-09-10n/aexe a1954b3233d9982d400046f616bbdf41f2e76aa11521cba382eb46de7a04a02cn/a 
2019-09-09n/aexe 24d5d04a71dbe53240a63238bdd4b1437334ab3e680f41ba95e415669b184f43n/a NetWire
2019-09-08n/aexe e63cc3f8f8b05717f902094b11a415d96c9853d9638f6f978191711fee946167n/a NetWire
2019-09-07n/aexe de6d83f952fbcf923350a1431533862bfd089627406a9b0d349a6a8075648f02n/a AZORult
2019-09-06n/aexe ad666306537eb35ffdc18dc953d51988baa1312a1a5ca394014abf56d0b6802an/a 
2019-09-05n/aexe be8b7677cd4daf54b6d50f60acdb0f11efa30129ff60b825b4f3c983d585120en/a 
2019-09-04n/aexe 6b08e46f2376cfec1eff2c22e607c4ff60e34442482c7a9469cb3c381fe561fdn/a NetWire
2019-09-03n/aexe f13769a0e1aaeb75f886719a5d4a22b0d4697df05701b935679eae92df1234e6n/a 
2019-09-02n/aexe 300109be347c94f02dbc67208e9088370ae2daf37a5b7317fc9a19bc8f410fb8n/a 
2019-09-01n/aexe 9b412eff3b3fd04218366bfecc33de87707f4a709e40fec04b08751f71463c76n/a 
2019-08-31n/aexe 0373dfda4d4e96c6a38a8c68c0b738939cbb39ab0549d1fbea10539ec1091c91n/a 
2019-08-31n/aexe 633cd45092ef3172fda8e5a821fcdd39ba6e81e752f3665d97e91190b228353eVirustotal results 43.28%