URLhaus Database

You are currently viewing the URLhaus database entry for http://sffacoglobal.com/UDD.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3730839
URL: http://sffacoglobal.com/UDD.exe
URL Status:Offline
Host: sffacoglobal.com
Date added:2025-12-10 09:53:42 UTC
Last online:2026-01-06 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-12-10 09:54:41 UTC to reportabuse{at}racknerd[dot]com)
Takedown time:26 days, 15 hours, 52 minutes Bad (down since 2026-01-06 01:47:26 UTC)
Tags:exe njRAT link xworm

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-22UDD.exeexe 370dbe0c8b2ef61959ccb6bcff27fc1eca766f665a07b7bd02259948a05e80d3n/a njrat
2025-12-16UDD.exeexe 84261daf375464a7da1820c7c6105ee7928b6bd564b7c4cd75472a88fa017337n/a njrat
2025-12-15UDD.exeexe 7942e847e6ff42dfce09d48fa80c44c901151a29aac8c9122804e777ed9e1288n/aXWorm
2025-12-13UDD.exeexe b71a58d3cc86496b4f714d9a3385bf8599bf09cd7092d6aac537786383948095n/a 
2025-12-10UDD.exeexe 49cfbce12333189d130fa3ca2b205a9c9d97223ca5509c11f4f96d9bf824b266Virustotal results 6.94%XWorm