URLhaus Database

You are currently viewing the URLhaus database entry for http://zenithgurukul.in/Setup.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2615437
URL: http://zenithgurukul.in/Setup.exe
URL Status:Offline
Host: zenithgurukul.in
Date added:2023-04-21 11:35:00 UTC
Last online:2023-05-03 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-05-03 20:31:09 UTC to abuse{at}publicdomainregistry[dot]com)
Takedown time:12 days, 10 hours, 50 minutes Bad (down since 2023-05-03 22:25:32 UTC)
Tags:dropped-by-PrivateLoader RedLine link RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-02n/aexe f5c94b63fcdeffffeaf2be235cc09f3d0e5db8587ddf4469d5605c7b44e2546en/a 
2023-05-01n/aexe a5b3f8fcc065b0387e858abb0787e9b0e98151869c825253cde183b6727e194bn/a 
2023-05-01n/aexe 1c78f3037b80458185afa166bb178f0c77e722b62c73d80126143d4abf9b6b26n/a 
2023-04-30n/aexe b428e179c0a5b9ac1fd02fd3f8cce9f883a5e5f521941e6a59b62d89a98e5fe5n/a 
2023-04-23n/aexe db88c0fad58337588ab4639df2a67b3cdec1d806962529561e2b4a2718c3986fn/a
2023-04-22n/aexe 69931ab63e612b27cad8c138de8cc54266acf0cbcdb27b88bcbe10ed422219d9n/a 
2023-04-21n/aexe 87109bdad7f20380518e8317885f3068fb4bcc299c71941af1ddcf2d4311cde8n/a 
2023-04-21n/aexe b86b793d720b43d3fb1525f98758256d1ccf4ed543dc1bd01b54921f7143fb46Virustotal results 18.57%RedLineStealer