URLhaus Database

You are currently viewing the URLhaus database entry for http://aurumboy.com/file1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:337938
URL: http://aurumboy.com/file1.exe
URL Status:Offline
Host: aurumboy.com
Date added:2020-04-10 14:00:10 UTC
Last online:2020-05-23 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-04-10 14:02:04 UTC to abuse{at}mgnhost[dot]ru)
Takedown time:1 month, 13 days, 0 hours, 50 minutes Bad (down since 2020-05-23 14:52:04 UTC)
Tags:AveMariaRAT link exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-05-13n/aexe 956924c4c488e005c78dc54ea5303ebb69544d21274c0afbce6e81ab0e7b21b7Virustotal results 68.49%1xxbot
2020-05-07n/aexe 047b9d4e3934e4279c5ed00a49a84db372335162707fca184c35b039481c8737Virustotal results 25.71% 
2020-05-06n/aexe 90f86036eefccf05415f8aa4eeb12f532bf9849d6d2b4326650a0778589e6ed3n/a 
2020-05-06n/aexe 29a77480a76a05724393efe87bc15706d3c74c36dce1ada3a2ca8c632dfc4dacn/a 
2020-05-06n/aexe 3e41a3b1206df8e5a9cb42fa6e26e89bc0cc72d18ed128beadd10aa0dce44834n/a 
2020-05-06n/aexe 7310d9b87d90bb647879dd9a7adc8cb76e0630dca1e15e75abfd0083203e83a2n/aRedLineStealer
2020-04-23n/aexe a6f3452b914f20bffe56053bf139726dab2b9a57ae6232198cf2371cb973a8d6n/a RedLineStealer
2020-04-23n/aexe 3a441a9c46244e96c4887394aa0f3dd19f6a44f4224e9d568deee8b8fdfec21an/a 
2020-04-22n/aexe 0722c53bd85b58e0519410c7bde76226274c45b5cc19b3a834694d7adcd4d4b1n/a RedLineStealer
2020-04-22n/aexe c93e26b307570a9b3fa749568a090d04cd94502df6fe2c9a131d9cf2bd5c8526n/a RedLineStealer
2020-04-10n/aexe 6893d4543596b246d71eb712a9936ada65e187b71a14616daa8c2a2012a12c0an/a AveMariaRAT