URLhaus Database

You are currently viewing the URLhaus database entry for http://ratamodu.ga/~zadmin/doc/aps.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:365948
URL: http://ratamodu.ga/~zadmin/doc/aps.exe
URL Status:Offline
Host: ratamodu.ga
Date added:2020-05-21 07:10:04 UTC
Last online:2020-06-04 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2020-05-21 07:10:09 UTC to abuse{at}selectel[dot]ru)
Takedown time:14 days, 15 hours, 12 minutes Bad (down since 2020-06-04 22:22:33 UTC)
Tags:GuLoader link Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-06-03n/aexe a4f594a78d5df595fe969cd0643707f5ca04aa10a7ef29f5617e3aa1e8db6d5fn/aGuLoader
2020-06-03n/aexe 1e7f88a0e73d63b2f6bbbb4c009b1eec11999ce62da1d3122473cabd502134c2n/aGuLoader
2020-06-01n/aexe 37d7bba1bacdbcb35e301c1fc391449ea84d1203ca59a8b1f1142acf4596e032n/aLoki
2020-06-01n/aexe 8db887fade310b044bf413542735e42ea639ba015a1442c1efaac57f6c37628bn/aGuLoader
2020-05-27n/aexe afa6acb992c2a3a3ee436a4627f8f5e0feed8e6a77dfa4ed6715069f12aef650n/aGuLoader
2020-05-26n/aexe f2e90acd9eecf1318a331ed9d7459caaff437e46c00ab2757f313d09002a4f94n/aGuLoader
2020-05-26n/aexe 7f97b36a796167d7d641a811c64ac23e7ff9998422308aec6d5753b9625f3729n/aGuLoader
2020-05-26n/aexe 460a85fda060cc0c8ab5a1aace37dc1f14bc400f4a3b011e613f64e0000c77b6n/aGuLoader
2020-05-25n/aexe ee2b02132ab9b2a6489c7ef37c853d2419924a2ca16940297851012a33fdee08n/aGuLoader
2020-05-24n/aexe 6dab870a5c920547d6a8a343244b15e61a764f4714a438c4212db404dc18f278n/aGuLoader
2020-05-21n/aexe b7853fa1e5921dd495975f697eb17ec18253ac022980855730598ef667ce9c2en/aGuLoader
2020-05-21n/aexe 1b0f25b9bf0c76f9a52d3f5952f47b203e7112c72f8234d51155442bddddd42fVirustotal results 1.39% 
2020-05-21n/aexe 1004b3957abb87dd5bd6a77a0b65930f32bb27a7121a10715ac8ca170619b024Virustotal results 19.18%GuLoader