URLhaus Database

You are currently viewing the URLhaus database entry for http://blue-yame-5396.penne.jp/AHU/FNK.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:366577
URL: http://blue-yame-5396.penne.jp/AHU/FNK.exe
URL Status:Offline
Host: blue-yame-5396.penne.jp
Date added:2020-05-22 11:14:13 UTC
Last online:2020-05-30 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2020-05-22 11:16:09 UTC to abuse{at}gmo[dot]jp)
Takedown time:7 days, 14 hours, 26 minutes Bad (down since 2020-05-30 01:42:15 UTC)
Tags:GuLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-05-28n/aexe 26f2158d9837aa986e3d69b6cb3df0ea039d0434cd504c2911ad9788bbbf7715Virustotal results 9.59%GuLoader
2020-05-27n/aexe 160684d9f79b0e33093a76315cbe47afd4d0f27f5dadd1b6fa314d8ff8a64370n/aGuLoader
2020-05-27n/aexe 1b161b9398f1f28f73c9bfaa6b536cc8bd49d1de076d78404f9a1fe181ec02b7n/aGuLoader
2020-05-26n/aexe 9848da60b74c19523583a237900008a3fcb268a9a4000c352f944f7d9f0d78e3n/aGuLoader
2020-05-26n/aexe 9848da60b74c19523583a237900008a3fcb268a9a4000c352f944f7d9f0d78e3n/aGuLoader
2020-05-26n/aexe a7cfec855ead8a33902aab33c3c217fbc6fe9fb372c4c8d0c1aec4b493736bf5n/aGuLoader
2020-05-23n/aexe 88b9016ca27b117830d0551458312126f49feca182dcfbc8f4f5558c7fd4fdc1n/aGuLoader
2020-05-22n/aexe 7da13f666893614674036e4b2d04340ef8bccd4722e86a7753105a45b8bd502dVirustotal results 15.28%GuLoader