URLhaus Database

You are currently viewing the URLhaus database entry for https://www.pekj1403.com/aianl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3859550
URL: https://www.pekj1403.com/aianl
URL Status:flame Online (spreading malware for 22 hours, 38 minutes)
Host: www.pekj1403.com
Date added:2026-06-06 06:00:11 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Ling
Abuse complaint sent (?): Yes (2026-06-06 06:01:14 UTC to abuse{at}sioru[dot]com)
Tags:SilverFox ValleyRAT

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-06-07ainst86235863001.zipzip e7eea832bd5aead16f13ba04a242b161719ba66a3a8fe689cb36eaca15d3df5cn/a 
2026-06-06ainst86235863001.zipzip 7152060d9c12d7130c78d829fc86374b61ff181f187e1635c3e94ebf708f48b5n/a 
2026-06-06ainst86235863001.zipzip b2c87760a99b98aa6ca9c9cbc99cc7003d1cfda1ccafa59452a1b7d2b5eb0fa8n/a 
2026-06-06ainst86235862001.zipzip be4bd43f21df79419db703af8c20cc71bae4e2dac474ef0f087f7a4fe94868afn/a 
2026-06-06ainst86235862001.zipzip 5eddcab2a69f898badb76df481d89e10fe892dd742f969086f2688ccc189ece4n/a