URLhaus Database

You are currently viewing the URLhaus database entry for http://aaa.hfaiuegii.com/files/pe/uegg1115.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2435595
URL: http://aaa.hfaiuegii.com/files/pe/uegg1115.exe
URL Status:Offline
Host: aaa.hfaiuegii.com
Date added:2022-11-28 08:33:23 UTC
Last online:2022-11-29 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: andretavare5
Abuse complaint sent (?): Yes (2022-11-28 08:34:08 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 month, 2 days, 21 hours, 10 minutes Bad (down since 2022-12-31 05:44:20 UTC)
Tags:dropby fabookie PrivateLoader

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-12-14n/aexe 32b579bec32e66d3199601167b9d5758994dfbba94491f39fb96e01a757b7ac7n/aFabookie
2022-12-12n/aexe 5a7cf98eb96522dd895785a421fdc490ca0d3e56dae80a72b4ad46d9d13f9452n/aFabookie
2022-12-09n/aexe a65ded6848a091217b4b932b260552bc0dac1843bc3e4f4bd63a40fd73f0a218n/aFabookie
2022-12-07n/aexe b55375af99e54da2ae6877ff642c5b85a0238992c0ae5b3703d1e0b650cf090bn/aFabookie
2022-12-04n/aexe 39647db3c833b5c8d8cbf4125123e0451f30d84da782fa379088515a63465cfan/aFabookie
2022-12-02n/aexe f264683bedd5dd7ace56e8c86084c2e7212251eb10b59108b8c70355ec1b25d5n/aFabookie
2022-12-01n/aexe 4e9f4aade314e825cca509e6d0aafcc2dd3eda43793451ce7a56b217b71b9ae0n/a 
2022-11-28n/aexe adc91b86359875df0149a283a6dbf6c11a9d6e4fd494c1340f20b3324571bddan/aFabookie