URLhaus Database

You are currently viewing the URLhaus database entry for http://mail.check-time.ru/ghjk.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2758224
URL: http://mail.check-time.ru/ghjk.exe
URL Status:Offline
Host: mail.check-time.ru
Date added:2024-02-08 07:22:09 UTC
Last online:2024-03-25 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2024-03-25 00:20:10 UTC to abuse{at}reg[dot]ru)
Takedown time:1 month, 15 days, 17 hours, 6 minutes Bad (down since 2024-03-25 00:29:49 UTC)
Tags:32 exe Rhadamanthys

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-03-20n/aexe b7bc6a1a992712c3d9f362475e731448ce32e355f6d8dbf7e0627daa77d4df41Virustotal results 56.16% 
2024-03-20n/aexe 6e923723b192744a56d891c06d7409d1d95d1c316034418618264f1a51462dean/a 
2024-03-18n/aexe 0dd11d652d9105db0ab187d009a5b103b56dae6a683b6c723ba4a173bd8b4f72n/a 
2024-03-18n/aexe be73738191878fdc49c8994b60069df39e835b6bae6a4a8ded041c87b8514e1dVirustotal results 43.06% 
2024-03-17n/aexe ded6a54094677ca3f18871f9a604deeedf06e38618b56e77ad809deaec887416n/a 
2024-03-17n/aexe 719e3ddb0bd552ed9f8f34c1ba19950038c72509185cfdbe8deddc7b91b51a51n/a 
2024-03-16n/aexe a0562f8a6eb7d21a633e4b2de55543def2d53d3d068bd866f2f2faac6df2735fn/a 
2024-03-16n/aexe b0c8e29bc0b9c6d05c1903e8681ed9779776a4282b60cf6b4c3a240333c6f574Virustotal results 52.05% 
2024-03-15n/aexe 4adfc166b70bd58e7495a522d525048d41481f6d024ce4be1e63153a982f4746n/a 
2024-03-14n/aexe 8a4f7f3280f1a5c35335be4309d2db8c1947b5168427ac80cd7793336bc5469fn/a 
2024-02-08n/aexe 217fbf967c95d1359314fcd53ae8d04489eb3c7bdc1f22110d5a8a476d1fc92eVirustotal results 79.17% Rhadamanthys