URLhaus Database

You are currently viewing the URLhaus database entry for http://rainbirds.ac.ug/zxcvb.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:365007
URL: http://rainbirds.ac.ug/zxcvb.exe
URL Status:Offline
Host: rainbirds.ac.ug
Date added:2020-05-19 20:57:11 UTC
Last online:2020-05-29 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-05-19 20:58:04 UTC to abuse{at}selectel[dot]ru)
Takedown time:9 days, 10 hours, 29 minutes Bad (down since 2020-05-29 07:27:13 UTC)
Tags:ArkeiStealer link AZORult link exe RaccoonStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-05-27n/aexe a8c4819383dd56652ece8564037c30367bc2f1b6f13fcd6fe6bec532eaf4762bn/a 
2020-05-24n/aexe 15145ed8e5ae3cf2acf9ad25bbcb3f782c4d8ba9674185d06baa66ae6d17f25an/aRaccoonStealer
2020-05-23n/aexe 9788eb6db83aafc366fbb615958f3a67c5d9c62d1ba87694aef12a30adfc9cb2Virustotal results 15.28% ArkeiStealer
2020-05-20n/aexe 7d02ae5ae3ed3b7a13ff5495174216ea3195764d7154b8e9b4997c74fd08fb09n/aRaccoonStealer
2020-05-19n/aexe 6b4c217c0bdb4660db2d83a8deb9e538e801e8c275e5e1fe955497970daf24c0Virustotal results 17.81%AZORult