URLhaus Database

You are currently viewing the URLhaus database entry for http://fransceysse.ac.ug/ghjkl.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2627575
URL: http://fransceysse.ac.ug/ghjkl.exe
URL Status:Offline
Host: fransceysse.ac.ug
Date added:2023-05-09 08:37:15 UTC
Last online:2023-05-28 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-05-27 12:04:05 UTC to support{at}zerohost[dot]io)
Takedown time:3 months, 10 days, 15 hours, 14 minutes Bad (down since 2023-08-17 23:52:40 UTC)
Tags:AZORult link CoinMiner exe Rhadamanthys

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-08-07n/aexe 29f5a8629986da0b4a353e5423fb39c505cba7c06e7aa4b5a4029c5a1669ae95n/aRhadamanthys
2023-07-28n/aexe b7398f53dd106d0d344faee6d5e6ce71637cad389d3efdcdf7031f45ed1d5bddn/a
2023-07-19n/aexe bcf3266e8996bcdb7acb686034f264b07c228ce37f1212b663b636cc0317ee1aVirustotal results 26.76% AZORult
2023-06-25n/aexe fc6ddb1f7644597b84d14e3efa4cd1a1d1ad0083141b3fa2a613cd3c092f6505n/aRhadamanthys
2023-06-19n/aexe e9acb123d1776dfdbb49bd7fa1dddda08c89d02bfd7b15cb3c08dbd16f17a07bVirustotal results 18.31% 
2023-06-03n/aexe a88eb8806c35881af91dd142c93cbda393ce9e42a83c5368ee6b21cc04f360c0n/a 
2023-05-28n/aexe 5d2e841645576d0eefcc6bcc6c0d480c0c6874f05a56e92441319a5c41b38979Virustotal results 35.21% AZORult
2023-05-12n/aexe bf1d731a91e424fd67778f176ac652fa5ca39f2ab188ef740184e4b2808c7b3cn/aAZORult
2023-05-11n/aexe 79a7c9d15971c14d78baccbf211b3ca1e9adcb0befc6d3d1c5d92902d70678e2Virustotal results 56.52%AZORult
2023-05-09n/aexe 84c18f78f11b9bc3fd3e96925d2a7b76ab5ecfb927c377ad27456e191815b24aVirustotal results 63.77%CoinMiner