URLhaus Database

You are currently viewing the URLhaus database entry for https://1h.xeteloi4.ru/vywerrzo27.hta which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3612153
URL: https://1h.xeteloi4.ru/vywerrzo27.hta
URL Status:flame Online (spreading malware for 1 year, 0 month, 4 days, 16 hours, 10 minutes)
Host: 1h.xeteloi4.ru
Date added:2025-08-26 19:06:09 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2026-08-25 17:30:27 UTC to abuse{at}linode[dot]com)
Tags:ClearFake

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-08-26vywerrzo27.htahta 2dd9e10629fa2d5cadd1414b878f33cfb7d6e1d5278b4506f13b4c8dafcd0aean/a 
2026-08-26vywerrzo27.htahta 6c3e7b3e2ec1f0448301f0309946459d0e10eaa021231c730a383bc3b67f4604n/a 
2026-08-26vywerrzo27.htahta ba02e4117514e7d69bb19c9f96c01d5b69b530a9bbdd93be45b97d4a9f502be8n/a 
2026-08-25vywerrzo27.htahta 0e47825b38a8b078af16722ff4f49e6988cd2dd1e1faf8062934e3970d13f5ebn/a 
2026-08-25vywerrzo27.htahta be8a1f5da191fe2c57642e9b1057c6b2dfe581bf6f8be2f01d942274849a064bn/a 
2026-08-25vywerrzo27.htahta 1af476c59ae9c2b729bc399900524d6a906ff7578dbdc736f642305bdebc6a03n/a 
2025-08-26vywerrzo27.htaunknown 6d0d77e639d5062d7fc34b0ef354ea25fee4e1c9fc31502841f08b5342c31632Virustotal results 0.00%