URLhaus Database

You are currently viewing the URLhaus database entry for http://ji.jhia6gy44dd.com/m/ss47.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2581804
URL: http://ji.jhia6gy44dd.com/m/ss47.exe
URL Status:Offline
Host: ji.jhia6gy44dd.com
Date added:2023-03-23 06:21:10 UTC
Last online:2023-03-31 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-03-31 19:15:08 UTC to abuse{at}scalabledns[dot]com)
Takedown time:9 days, 1 hours, 41 minutes Bad (down since 2023-04-01 08:03:59 UTC)
Tags:exe fabookie

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-03-30n/aexe 3e81789659a8623bc23c25a8010057f9fca72e5c853b1a874c7e6183f7cdf12an/a Fabookie
2023-03-28n/aexe 4a6b10636d9b2e8d224fe2c137592e1be01cbaf5b9b2b4d7dacb7a96edd7d7b5n/aFabookie
2023-03-28n/aexe 80da4c81dc96eedadac2765885a111e441d956803cd4a85d8f7458dd5464eecen/a Fabookie
2023-03-27n/aexe 5b6a3b0e00cae8eb8d49dc47681632844778e948283dad2c3f89d826d9eca780n/a Fabookie
2023-03-26n/aexe c73421f08cc2983e98378f1998eb9c7097be5d5c66d31b2f71367bfe861cf4d5n/a Fabookie
2023-03-24n/aexe e5f399d301ce1d2cf5fdb3664d93017ef32847651277461a69b1c254f81d601en/a Fabookie
2023-03-23n/aexe 4ce00d8852d8faa23e7722e142ac29ebea94e678c6bdc48120cd98afe843fb26n/a Fabookie
2023-03-23n/aexe 43e4574bbe757104766b7299c8ebf76026f0932b079e6a0ecd4325f6c0ddb36fn/aFabookie