URLhaus Database

You are currently viewing the URLhaus database entry for http://partadino.ac.ug/ghjkl.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2654454
URL: http://partadino.ac.ug/ghjkl.exe
URL Status:Offline
Host: partadino.ac.ug
Date added:2023-06-07 05:29:07 UTC
Last online:2023-11-12 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-11-12 14:06:05 UTC to petr196721{at}yandex[dot]ru)
Takedown time:10 months, 17 days, 18 hours, 52 minutes Bad (down since 2024-04-20 00:22:59 UTC)
Tags:32 AZORult link CoinMiner exe Rhadamanthys zgRAT

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-03-27n/aexe 432747c04ab478a654328867d7ca806b52fedf1572c74712fa8b7c0edb71df67Virustotal results 29.17%CoinMiner
2024-03-20n/aexe d7ce73fdfb55b4803cc0b86734ed4f077b3ca4fb11f18d55a0da35f90e759d24n/a 
2024-03-19n/aexe 9fafef74dfd5bda662cb78e16211f6a7ee765b619e8092594f30b98a52835f0fn/a 
2024-03-17n/aexe ed1fe24d289ac0f191b3226052c374e9c7ac53c7cf20bb349c360e1bfdca175en/a 
2024-03-17n/aexe 52bceda6ff07125e2899b042f7715dd754b4e8a560892483be99b696a51680a6Virustotal results 46.58% 
2024-03-16n/aexe e2384adc5c5418182810846cb3bbe46999a174bf1bd8a7db5060ec69b6d1dabdn/a 
2024-03-16n/aexe 6a65ff3bb8350beba39868a4b645dffe4f8dd5fc529095ed8e432f6bf2057903Virustotal results 58.90% 
2024-03-14n/aexe cc8a2e6eadf17b7b3a9063bfe899dcab4193366e0b8a330217c7fd0b735e9b01n/a 
2024-03-14n/aexe 33182115e8ccf4b279e32846761b90f05efaae00549c7f46cb3ce65702c9b6e1n/a 
2024-01-30n/aexe 217fbf967c95d1359314fcd53ae8d04489eb3c7bdc1f22110d5a8a476d1fc92en/a Rhadamanthys
2023-12-04n/aexe 189051c29319fac6a96fefc8158f9d27d61a55b668f3c8e3610a48617649518fVirustotal results 48.61%zgRAT
2023-11-12n/aexe ad7af6aca0ba3d2fe9adb3f391800420800c0f6aa00db064fc1292232a6d881eVirustotal results 40.28%zgRAT
2023-10-26n/aexe 8868ea6af3214fc758c93c1cb909231a76e22e718a4917aae5f2a60cf12af094n/aAZORult
2023-10-15n/aexe 22224f65c07515b2f61e29f7f1a14005d0de54378aa925d9e017bb2ac26b5395Virustotal results 41.67%zgRAT
2023-10-12n/aexe a6c7b60910aca6fe34c79df28e7248f9039a61c4391d669cdf117b2dc4b6e6c6n/a 
2023-10-04n/aexe 77bfa9410910904d05a73ad3d6c28c1aa02b9d2ec82419f73600615b8b27f9a2Virustotal results 40.28% Rhadamanthys
2023-08-25n/aexe 56c72842d1cc17774f0698aeb9747330cd4e18393deec2f31a9d4d7645713ea8n/a 
2023-08-07n/aexe 29f5a8629986da0b4a353e5423fb39c505cba7c06e7aa4b5a4029c5a1669ae95Virustotal results 45.07%Rhadamanthys
2023-07-19n/aexe bcf3266e8996bcdb7acb686034f264b07c228ce37f1212b663b636cc0317ee1aVirustotal results 26.76% AZORult
2023-06-25n/aexe fc6ddb1f7644597b84d14e3efa4cd1a1d1ad0083141b3fa2a613cd3c092f6505n/aRhadamanthys
2023-06-07n/aexe 5d2e841645576d0eefcc6bcc6c0d480c0c6874f05a56e92441319a5c41b38979Virustotal results 80.28% AZORult