URLhaus Database

You are currently viewing the URLhaus database entry for http://zaragozsa.ug/zxcvb.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:401281
URL: http://zaragozsa.ug/zxcvb.exe
URL Status:Offline
Host: zaragozsa.ug
Date added:2020-06-24 06:26:43 UTC
Last online:2020-08-17 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-06-24 06:28:02 UTC to abuse{at}grandcosmetic2[dot]ru)
Takedown time:1 month, 23 days, 21 hours, 16 minutes Bad (down since 2020-08-17 03:44:10 UTC)
Tags:AZORult link exe NetWire link RaccoonStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-16n/aexe 308c96557c6be5d4519ba4bac38c23e611c7b61683cfc1063a6009e216c24f5en/aRaccoonStealer
2020-08-06n/aexe b7b4548520de8927b3457b599a4b3afb3b686de57dd4b186c2c7ee6c00524377n/aRaccoonStealer
2020-07-30n/aexe 07dd81aa4994d15fd4d26bb4b9a4aa5dff47d99da2ab76718f480f62cb4ddb93n/aRaccoonStealer
2020-07-23n/aexe f153e1bf81a8faf42cff46480b58bf538a3a7c6085b2e67facc94ea8e879eca2n/a RaccoonStealer
2020-07-17n/aexe aecddb3a9656759f5681708172573f435c3db0539d6a7a0230ec93b4e3f131a1n/a 
2020-07-14n/aexe 3b0d6b26dd2152ce85b4487777afc66e2ea37f33697d6ffe07608b79ffd47614n/a 
2020-07-12n/aexe 3d4820c098548ddeb284389d43bc1ce29b4171bae99de28f83727624377b4f21Virustotal results 17.14% 
2020-07-10n/aexe 57fa7385d4d9d98c498ed421e98cc5900ca489703055af7ccf0edff69c1fe749n/a RaccoonStealer
2020-07-08n/aexe 07145b3504f4fe39434718b6b68fdecc52c909e135271f5461488f7b23c7b55fn/a 
2020-07-01n/aexe e4692010fd3d0a88db68face738f5538ec067e3d2066f8d45ff1fe84ba5cb09dn/a 
2020-06-28n/aexe 3e9f05acde528ea5fd7ca9d0c2af0e82d29e343d2f61420290e6f660630cd25fVirustotal results 20.55%NetWire
2020-06-24n/aexe 682be0853ccd6f60deb69d27941a628758c4e13e7d2e6ee95a95f415f3a9f0c6n/aAZORult
2020-06-24n/aexe 14de928a31f94b3595d463b72256c95f0cbe43e893f646fb350785f5fb00f0a2Virustotal results 65.75% RaccoonStealer