URLhaus Database

You are currently viewing the URLhaus database entry for http://cassiagumrefined.com/js/file/NG90/89NTb.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:348812
URL: http://cassiagumrefined.com/js/file/NG90/89NTb.exe
URL Status:Offline
Host: cassiagumrefined.com
Date added:2020-04-23 12:22:04 UTC
Last online:2020-05-02 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: oppimaniac
Abuse complaint sent (?): Yes (2020-04-23 12:24:04 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:8 days, 23 hours, 56 minutes Bad (down since 2020-05-02 12:20:14 UTC)
Tags:exe Formbook link GuLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-04-29n/aexe a63dfd81e0eb6283bc0051a3c1f80ba0eb818d132aafe5e6a1cc3cd63a3433ffn/aFormbook
2020-04-28n/aexe b12ef83752daeb6755b31cce4d8367246b380fc4d8d5bfd5e42e36f34df5c8d6n/aFormBook
2020-04-28n/aexe bd4e6fad01c570c9f91de1385bae851f8c5498428de7d998dc874eb5f682ea6fn/a 
2020-04-27n/aexe 77839da1c15d6390080afe07320af399a007d5b69bf4fcdf63fc71e795929cf7n/aFormBook
2020-04-27n/aexe e3e778591453a54d2cbd3ab1bb4ecb69ed94222f248aac24a95fb951fc6101f0n/aFormBook
2020-04-26n/aexe 6c80262419efb953f1617c2edb188d5e71b3fd97585079648fc8853720e3f358n/a FormBook
2020-04-25n/aexe 677f8495a56223da5a8f115113ae3f1f62b7214a6dc2b303961c924d4a9c562cn/a Formbook
2020-04-25n/aexe 1e9ce0d6760bfc646d3ebfe2c2bf4ff35ac84bf622f8fbd734568d38db7cbb33Virustotal results 26.39% FormBook
2020-04-24n/aexe 211de7b1e7e6ff80740ca2ba9bdeed8ff09efed28730a6c38b23beba951c70a3n/a 
2020-04-24n/aexe 737a78cd3f87205b5bc984ef9fc3b8a52a850cb5ef29a3ee0b77009b73136423n/a 
2020-04-23n/aexe c66780084ccdea3bf906a9e483927030485eb753e9796a9ff489a6330b28acddn/a 
2020-04-23n/aexe dea51f7f074a8d9b0e30626e11ca4a79de602da24ba64d0222ee1162a5fbb5ban/aGuLoader