URLhaus Database

You are currently viewing the URLhaus database entry for http://31.41.244.12/files/document.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3279832
URL: http://31.41.244.12/files/document.exe
URL Status:Offline
Host: 31.41.244.12
Date added:2024-11-07 06:14:05 UTC
Last online:2024-11-22 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-11-07 06:15:16 UTC to dl{at}redbytes[dot]ru)
Takedown time:15 days, 13 hours, 47 minutes Bad (down since 2024-11-22 20:02:34 UTC)
Tags:AsyncRAT link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-11-21n/aexe b3e217c467cfe1e8079e82b88f2f99950a9459330a8843070ebb34bf3e2bcf38n/aAsyncRAT
2024-11-17n/aexe 44f611726336cec3fa65ba287bf135af2cd43c6441ead65ce4a54c154ea80f90n/aAsyncRAT
2024-11-14n/aexe 3453572f3252f42abc0c1ea433f8df6c1a8997621c91a916d1700892dc3f9a3fn/a 
2024-11-08n/aexe b738ac1ae6debdb89df7e074577c1f0c12dfb80fa6cb708e08f168b744386a6bVirustotal results 41.67%AsyncRAT
2024-11-08n/aexe 6f29de59bd022c91ea367bf1c0dbe58fb51f410d97e974ddbfdee97ad08b5807Virustotal results 37.50%AsyncRAT
2024-11-07n/aexe 1eeb804cdda18bacd4205a1c25ac6a835f0dac3e7d89ccae111c3e1d449b54a3Virustotal results 44.44% AsyncRAT