URLhaus Database

You are currently viewing the URLhaus database entry for https://fidarshimi.com/anz/OpenVPNGUI.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2308260
URL: https://fidarshimi.com/anz/OpenVPNGUI.exe
URL Status:Offline
Host: fidarshimi.com
Date added:2022-09-20 13:49:07 UTC
Last online:2022-10-22 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: andretavare5
Abuse complaint sent (?): Yes (2022-09-20 13:50:24 UTC to abuse{at}hetzner[dot]com)
Takedown time:1 month, 2 days, 1 hours, 5 minutes Bad (down since 2022-10-22 14:56:21 UTC)
Tags:dropby N-W0rm PrivateLoader RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-22n/aexe f5977f994ee65abdf950c4db5ae9001bca8c2bc9d3c1a7ff03a52aefd402c5fcn/a RedLineStealer
2022-10-22n/aexe 5cbadb97c7ce8adfb83760042a214ff7a9fdf447a8ce6c91ec19f3dcd4f6c4c9n/a RedLineStealer
2022-10-22n/aexe 3ee75f6a4b31115d1392af5ef893b6dc7ea30305bfb249d49ce1cd33aa1d0f97n/aN-W0rm
2022-10-22n/aexe 7b39a3a66d3611ac2026161cf8a01fe2447092759544e996e9be16a96eff04fbn/a RedLineStealer
2022-10-19n/aexe 96574697cdb53f062b239c4252a3c9aa85376ed566389eb48d7aae0418df4318n/aN-W0rm
2022-10-19n/aexe a0bf7c1184092027ccea8b4381e7f359662bcc317ac4c7a2e02459d1b66d9da6n/aRedLineStealer
2022-10-19n/aexe 783559e98939ca1bc184e1e6af99b43ca6a2bbcb4ce7c2734f42fceee1fb0504n/a RedLineStealer
2022-10-19n/aexe 3d053bf98b77d7617b0edb6e6e050d215c6d8270b7a10d97034c0e46f4375a08n/aRedLineStealer
2022-10-19n/aexe c8724d7d7c8e9c054c52905cc8469d87f4e8d16bdc1a013a8ea983690e43a2can/aRedLineStealer
2022-09-21n/aexe 84bffe0134a76cc4fe3a3addab50d85b781f57bd6c4693a04321164b691b8c00n/a RedLineStealer
2022-09-21n/aexe 01b5ee4fd24c7814df0d3dfd4b7bdc892825774127bd8350a037ed33e4565168n/a RedLineStealer
2022-09-21n/aexe 1adc5e81a85f915acdac460c01a69f6cd0f36114ebb5ef94f8fa41613a657dd2n/a RedLineStealer
2022-09-20n/aexe 6bcd31b82da0322f6e356f503bb3ca2b0c1ade0482632322e2d0136ea4775ba1n/a RedLineStealer
2022-09-20n/aexe 83c2020440b15c4301f2aa7528ab6a317adab793762ee17c0aee9ef717f1bf69n/a RedLineStealer
2022-09-20n/aexe 15602b31720fe3af143d179633ad7be007e46579f4613bc25c633bc4c8cbebf9n/a RedLineStealer
2022-09-20n/aexe 1fda2d1c1c161e51b6ac01ce6503d62782493417339cb1304a07cbd6f2ff98een/a RedLineStealer
2022-09-20n/aexe 53ebdf6d62e1aaa7d1ade0a1d7fcbe95e6967a723b6e3c531961bae78afabf2bn/a RedLineStealer
2022-09-20n/aexe c94d30cedc3657bce5ed5a06633cb83adf6b18f253c6ced01462d0a891dd4123n/aRedLineStealer
2022-09-20n/aexe 4be839ef16079be8c184fae241e067b607860f60c7cc45f4de438f0ab1ec722eVirustotal results 40.85%RedLineStealer
2022-09-20n/aexe 5ea64524fc886f66d5b3aa5311e2daa4c033a9a23104bfea0829b0f46a26d264n/aRedLineStealer
2022-09-20n/aexe c0908595a7264db050cdfc6067b6193935fa95812ea93d0a167748f6e34149a7Virustotal results 35.82%RedLineStealer
2022-09-20n/aexe cc04d694f64cf0c0e875c279d0aca58c18fe6796dfd94282b61039d400126900n/aRedLineStealer