🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for https://yellowstone.com.mm/rahu/?35697121 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry



ID:2715769
URL: https://yellowstone.com.mm/rahu/?35697121
URL Status:Offline
Host: yellowstone.com.mm
Date added:2023-10-02 13:33:35 UTC
Last online:2023-10-05 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: marjatech
Abuse complaint sent (?):mail Yes (Ticket DCU100266329 created on 2023-10-03 01:41:02 UTC)
Takedown time:2 days, 0 hours, 9 minutes Poor (down since 2023-10-05 01:50:48 UTC)
Tags:DarkGate link TR

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-10-04Test_395-13959.zipzip 88b5e4b1b533c398d790fbe974b2b369d72268069dcc64b53a742f4d1361c6bfn/aDarkGate
2023-10-0469.xlldll e9d42a6d52380fc47e8be592478bda6a46ad4e40cefc08d33f9031a4ebbcf971n/a 
2023-10-030C.zipzip 8b6a961422d8520f2b9d7e5e2805324c1e5f5161a8b4f9c555c91fffe4236781n/a 
2023-10-034ZJO.zipzip 6b06ec59f2582c60b4962b8f2d0b488c323f9cd2e4fc60014013a97abb5bd872n/a