URLhaus Database

You are currently viewing the URLhaus database entry for http://ratamodu.ga/~zadmin/doc/bill.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:366100
URL: http://ratamodu.ga/~zadmin/doc/bill.exe
URL Status:Offline
Host: ratamodu.ga
Date added:2020-05-21 09:19:36 UTC
Last online:2020-06-04 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-05-21 09:20:09 UTC to abuse{at}selectel[dot]ru)
Takedown time:14 days, 13 hours, 2 minutes Bad (down since 2020-06-04 22:22:28 UTC)
Tags:exe GuLoader link Loki link Pony link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-06-03n/aexe f505dd338ac82bc130bc50c89b509c371bb87e901842e64a12fd35749bf8b3b6n/aDownloader.Pony
2020-06-03n/aexe 893348cfa61e59048f8444685df09b3f6dcb22b84995427ba4cff095ee53896cn/aGuLoader
2020-06-01n/aexe 4b632e01957edd0717ec241f31b52bee90b2060d1a99e1467c842f0241d68d02n/aDownloader.Pony
2020-06-01n/aexe 729c73ab057bc16133a582db643fc4654c806e76fa70d98dd82923b4f198c285n/aDownloader.Pony
2020-05-27n/aexe 1ea235444a0510aeabcc31b2092268c3d0d12d82130ad2cb4b9024246e54186bn/aDownloader.Pony
2020-05-26n/aexe 90f3c7b548e9f8d7477d4d1a2b8ea2bc2fcf26d36c79706e869fb9ded4813dfen/aGuLoader
2020-05-25n/aexe 11ee988764e0e77d4f2eb76229e59a1a8239b84ac1abf2ce8bf729c985531e72n/aGuLoader
2020-05-24n/aexe 0844334598a3afd4d6c303956a1e56247c59e369b837b71ff31a55d1b404a4bcn/aDownloader.Pony
2020-05-21n/aexe 7896a69d4b9f99ec3ee75220edb376cdbb4905e35a9a4774060054a2827d2978n/aLoki
2020-05-21n/aexe 1b0f25b9bf0c76f9a52d3f5952f47b203e7112c72f8234d51155442bddddd42fVirustotal results 1.39% 
2020-05-21n/aexe 3718ecafddb6b2fcf35611ec2b060d06de6243ca971124177f8dab5c0dfbbe0fVirustotal results 26.76%Loki