URLhaus Database

You are currently viewing the URLhaus database entry for http://fran.ac.ug/ghjk.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2627573
URL: http://fran.ac.ug/ghjk.exe
URL Status:Offline
Host: fran.ac.ug
Date added:2023-05-09 08:37:12 UTC
Last online:2023-05-29 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-05-27 11:40:08 UTC to support{at}zerohost[dot]io)
Takedown time:3 months, 10 days, 16 hours, 9 minutes Bad (down since 2023-08-18 00:47:40 UTC)
Tags:AZORult link CoinMiner exe Rhadamanthys

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-08-07n/aexe 29f5a8629986da0b4a353e5423fb39c505cba7c06e7aa4b5a4029c5a1669ae95n/aRhadamanthys
2023-07-19n/aexe bcf3266e8996bcdb7acb686034f264b07c228ce37f1212b663b636cc0317ee1aVirustotal results 26.76% AZORult
2023-06-25n/aexe fc6ddb1f7644597b84d14e3efa4cd1a1d1ad0083141b3fa2a613cd3c092f6505Virustotal results 33.80%Rhadamanthys
2023-06-22n/aexe debcbca227d6b6c28d5f914e8d1d265834269de608373e2d2cdd299dbbc6032an/a 
2023-06-20n/aexe b0a921079fc1d5656820c576b3e9175bd8656f047f2de3b569a0f9d08130ce66n/a 
2023-06-17n/aexe 56d2c64746de74c42d6e7e658089071a29ac6b041b70c320ceec21bc5fd83769n/a 
2023-06-01n/aexe 5225e9b327a111e5a83aa6e724c3433444bc8651fb583b0dd637724fee486d40n/a 
2023-05-28n/aexe 5d2e841645576d0eefcc6bcc6c0d480c0c6874f05a56e92441319a5c41b38979Virustotal results 35.21% AZORult
2023-05-12n/aexe bf1d731a91e424fd67778f176ac652fa5ca39f2ab188ef740184e4b2808c7b3cn/aAZORult
2023-05-11n/aexe 79a7c9d15971c14d78baccbf211b3ca1e9adcb0befc6d3d1c5d92902d70678e2Virustotal results 56.52%AZORult
2023-05-09n/aexe 84c18f78f11b9bc3fd3e96925d2a7b76ab5ecfb927c377ad27456e191815b24aVirustotal results 63.77%CoinMiner