URLhaus Database

You are currently viewing the URLhaus database entry for http://kstarserver17km.club/crot777amx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:247378
URL: http://kstarserver17km.club/crot777amx.exe
URL Status:Offline
Host: kstarserver17km.club
Date added:2019-10-22 05:14:05 UTC
Last online:2019-10-23 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: JayTHL
Abuse complaint sent (?): Yes (2019-10-22 05:16:06 UTC to noc{at}psychz[dot]net)
Takedown time:1 day, 4 hours, 36 minutes Poor (down since 2019-10-23 09:53:05 UTC)
Tags:QuasarRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-10-23n/aexe 215d6ffc2091d25b6580bd944feb6bf60be187553b6fcf593801adb3f10d41fen/a QuasarRAT
2019-10-23n/aexe 0f73b191ece661314085496e5f92aca9bd5d724a8832fa24d6e89e9fcfb41e52Virustotal results 25.71% QuasarRAT
2019-10-22n/aexe 498ee257d3bc1a911ffaae40a3430ba9320dd97c0c881af171232fa1b72d6d99Virustotal results 30.00% 
2019-10-22n/aexe bff260d107c144ba6b6db2e332ebc3470584b763d7247c8b7ad016d735ea1cc9n/a QuasarRAT
2019-10-22n/aexe 2ccfe0af66faf271d6006c7c9e34d7c46efcb6fd0fbbcd8f032a78ef9752662bn/a 
2019-10-22n/aexe 14e361a140e854735b413069cbc8e2a2c27ab00b2133a87cb5957bcc999d7426Virustotal results 34.29%