URLhaus Database

You are currently viewing the URLhaus database entry for http://jask.powerforxes.shop/yuop/66afa0d3934d8_ultfix.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3212782
URL: http://jask.powerforxes.shop/yuop/66afa0d3934d8_ultfix.exe
URL Status:Offline
Host: jask.powerforxes.shop
Date added:2024-10-04 19:16:34 UTC
Last online:2024-10-22 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-10-04 19:17:10 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:17 days, 21 hours, 55 minutes Bad (down since 2024-10-22 17:12:25 UTC)
Tags:exe GoInjector RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-18n/aexe 0d072464344350e7b8320b6dc1c9e75d98c38ee7334ec0abfae97fb589205da8n/aGoInjector
2024-10-17n/aexe 794d5c5b2f47ac3ee5d750fd898deddc51e27ddec32253c52ce3af3a0b966ae3n/a 
2024-10-14n/aexe cf4ef7aae9dd5dda079e43e26167a5f7debb9ccc9f335bebaebbc5e28fa35965n/a
2024-10-10n/aexe 18da43fa2569a90e892b2b77505c5cb5f5f4b67a2cc40a160b5a2778b3a736e2n/a 
2024-10-04n/aexe a0906077d04dbccf4fdcaa15f49f5d214bfdb2baf845126d44ff638f620681bfVirustotal results 66.67%RedLineStealer
2024-10-04n/aexe 0da05d5b18649c9893161a679eec7d2ff0f4d7c31369761e9243d15c118101c9n/a