URLhaus Database

You are currently viewing the URLhaus database entry for http://nkfd.jahhaega2pp.com/m/llaa25.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2639010
URL: http://nkfd.jahhaega2pp.com/m/llaa25.exe
URL Status:Offline
Host: nkfd.jahhaega2pp.com
Date added:2023-05-22 18:10:11 UTC
Last online:2023-05-23 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-05-22 18:11:08 UTC to abuse{at}cloudflare[dot]com)
Takedown time:5 days, 17 hours, 25 minutes Bad (down since 2023-05-28 11:36:51 UTC)
Tags:dropped-by-PrivateLoader fabookie

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-27n/aexe 1c3f105071705b63235fd6e1bc92b7de604218198a73173214945c250fe45f2an/a Fabookie
2023-05-26n/aexe 340a91310668a5a9ee94404f9bec196f180c6ea1c3a47124614918e02c480d40Virustotal results 7.14%Fabookie
2023-05-25n/aexe 948d145285365265a7a38d62e9281fa792a2896903f42c4de83f0ead8220e0d6Virustotal results 19.72% Fabookie
2023-05-24n/aexe 3945f9e4b33ca4afbaac6778951fed079a5d3a630159038c5dfd9e55f550d2d5Virustotal results 12.86%Fabookie
2023-05-23n/aexe aeb8f4b6bb3c7cf7117c6593d6c4e493bdeaec2e8babf2f6676c5166bc8238bfVirustotal results 2.86%Fabookie
2023-05-22n/aexe 0fbeaa3d0492f83c2351aa8f91c429f063700d1fee4aa355e439c0862f6bb41fVirustotal results 11.43%Fabookie