URLhaus Database

You are currently viewing the URLhaus database entry for http://igw.myfirewall.org/POWERPOINT.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3679148
URL: http://igw.myfirewall.org/POWERPOINT.exe
URL Status:flame Online (spreading malware for 1 month, 6 days, 13 hours, 0 minutes)
Host: igw.myfirewall.org
Date added:2025-10-16 05:38:10 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: johnk3r
Abuse complaint sent (?): Yes (2025-11-03 17:54:12 UTC to abuse{at}lanedo[dot]net)
Tags:a310Logger link AsyncRAT link DarkTortilla RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-18POWERPOINT.exeexe b10080bae74e176adab6a0df8eb5dbc50d661b5f7ac180069470712e9f89f290Virustotal results 39.44% a310Logger
2025-11-13POWERPOINT.exeexe 88fc71441cbb84f06e8d10c6aa5763581bb5bf39b8bc395e6bccb6c4aa184e70n/a a310Logger
2025-11-11POWERPOINT.exeexe f5746df1a4d266a2f7718fe251546dff7a8e3bbce8f766277df74f0145c69d11n/a a310Logger
2025-11-11POWERPOINT.exeexe 32573f4e04f0b44e5affbf056876a1775e7a17700bfaca2192bace2558803b91n/a DarkTortilla
2025-11-07POWERPOINT.exeexe 0ce7f7e617fd316d6b53ca238268560cc8e39509e6c3fa00058738f9319b2dedn/a DarkTortilla
2025-11-06POWERPOINT.exeexe 3dd20379c8c818739e6b82f3b89da56385a1555489e107354080dbd7c22a7e39n/a DarkTortilla
2025-11-05POWERPOINT.exeexe 1fe4d6a4437144cdd9af1d14111c0d52078d2e909aa4efdbb8fe512edda863acn/a RemcosRAT
2025-11-03POWERPOINT.exeexe 45902cefc70a547213f4c011a268b4f209c19fa5f5539bb52e0d1e06446c6435n/a a310Logger
2025-10-29POWERPOINT.exeexe 2234159417129ec303394a14cba991762d972e88020fb0fe2a8838392db9234dVirustotal results 35.21% a310Logger
2025-10-27POWERPOINT.exeexe c167d77c6b718bbdcdda8e7e0389488b4f76b884560e4663b79fcd828280a128Virustotal results 31.94% DarkTortilla
2025-10-20POWERPOINT.exeexe bd5fa7d360cd94de05b82d21fb4e35731b69c83e6bf8a17b81efcafea83de2a6Virustotal results 34.72% DarkTortilla
2025-10-18POWERPOINT.exeexe 6c22a1818f78be2dd32749140bfcaa6d930cf94984f1c58a8f21c1a2b0b27e35Virustotal results 38.89% RemcosRAT
2025-10-16POWERPOINT.exeexe de65498751e45e61b367395674e794ccd7e88f14c4661218a095b538ad0bca71Virustotal results 40.28%AsyncRAT