URLhaus Database

You are currently viewing the URLhaus database entry for http://igw.myfirewall.org/WORDS.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3679147
URL: http://igw.myfirewall.org/WORDS.exe
URL Status:flame Online (spreading malware for 1 month, 6 days, 22 hours, 42 minutes)
Host: igw.myfirewall.org
Date added:2025-10-16 05:38:08 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: johnk3r
Abuse complaint sent (?): Yes (2025-11-03 17:54:12 UTC to abuse{at}lanedo[dot]net)
Tags:a310Logger link AsyncRAT link DarkTortilla QuasarRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-18WORDS.exeexe 57607b9ff9f4aeb330e0a10dc78237e87fc0fa2bc922cfcbd5e4d2eae336e7a7n/a AsyncRAT
2025-11-13WORDS.exeexe 3a7772e29f89c0844024b2a9529109212fc15c824810bd52188a14fffcfb5571n/a QuasarRAT
2025-11-11WORDS.exeexe 16b2789f485c9dd68380887a499dac1c14dd66cc87628133b8e08c1fef1c1a41n/a QuasarRAT
2025-11-11WORDS.exeexe cf355d1f1a7066a2082089a149779b564e67a55620fc4ce3b332258522bf72fcVirustotal results 41.67% AsyncRAT
2025-11-07WORDS.exeexe 50518ea953dbd453921a6a2f8c705f5fe15ee2bbf2eccd71a691a44d66d96d47n/a DarkTortilla
2025-11-06WORDS.exeexe 9ed85aa4a3d198d809e49985a52ab2d5096f436ed10f0b3eae851ae16dba881bn/a DarkTortilla
2025-11-05WORDS.exeexe b976b6f5cd3a85b06c6d6987f2053aabaa3c30d42b0f9b429a632ae20c5e9a50n/a AsyncRAT
2025-11-03WORDS.exeexe 6136f085b3fdda0b103bac31b391f5f1fc785d2d2701006bdc3be6833e26738dn/a AsyncRAT
2025-10-29WORDS.exeexe 2eba126064eb79980aefe2b1efa1687864acbbce6e7d443bfa17d8532c0e9c34Virustotal results 33.33% AsyncRAT
2025-10-27WORDS.exeexe 66e34fa5c882a1583081b6102ebfcb1adedb87dcabcd386166e40c16be31ee09Virustotal results 52.78% DarkTortilla
2025-10-20WORDS.exeexe 9ef8c4e711ae89345bab3e24b0435fc0bbbb4ecb3fd9f4b471636a40cb497255Virustotal results 43.06% QuasarRAT
2025-10-18WORDS.exeexe 064587a3bba7adc805b9b9555a947c80dee486e85fd34c0aded83de6e5c80acdVirustotal results 56.94% AsyncRAT
2025-10-16WORDS.exeexe 26319845c08cea4e26c57a35308c7307847c693ed4108ecaaa344e8afe666b28Virustotal results 62.86%a310Logger