URLhaus Database

You are currently viewing the URLhaus database entry for http://zaragoza.co.ug/zxcv.EXE which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:401282
URL: http://zaragoza.co.ug/zxcv.EXE
URL Status:Offline
Host: zaragoza.co.ug
Date added:2020-06-24 06:27:19 UTC
Last online:2020-08-17 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-06-24 06:28:02 UTC to abuse{at}grandcosmetic2[dot]ru)
Takedown time:1 month, 23 days, 20 hours, 47 minutes Bad (down since 2020-08-17 03:15:28 UTC)
Tags:AZORult link exe RaccoonStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-16n/aexe 8bbb8fe69100550248f4663e911a16bca03432bef9112dd0924d7a9c3dae8464n/aAZORult
2020-08-06n/aexe 0e84226430bd428b5dd2f9ceb5cddba56ad3f6606a0b7bf978484132d753aa9an/a RaccoonStealer
2020-07-30n/aexe 286c2eb8755215619d8cb48cc884091251729d5925b74444fe3b62c2c1a5acb5n/aRaccoonStealer
2020-07-23n/aexe ac0bff3a87acefe245899d7f908a0e400d49d56b75b9ee6400ac58ea180e3e20n/a RaccoonStealer
2020-07-17n/aexe cdbf4a76ee56b8f26b29fccc6fb83c672ac897795554c660bb8bbd05acd22131n/a RaccoonStealer
2020-07-14n/aexe 5cd5861ce0c007ee7d09a79df1a93424ee1f4c2ed503b140e60ac22f6e5ece54n/a RaccoonStealer
2020-07-12n/aexe f16514ee7d82f75259d7e0081f96533640f6bdd8bba7bf47b6d0fa64bbf98e53Virustotal results 47.22% RaccoonStealer
2020-07-08n/aexe 69fe5bb4b975f9437b6c3bcf3f07dc807a8f2e848f1e0c5802012295b06a742cn/aRaccoonStealer
2020-07-01n/aexe 7dd09a71615dc2a60ba9dd906aebcff010f8442f4db392e4feb88baa01f8c999n/aRaccoonStealer
2020-06-28n/aexe a6a6ff46eafb272d4a37b1f943adde3e1406540277a0a4f1bc18e00e124922bfVirustotal results 47.89%RaccoonStealer
2020-06-28n/aexe a6a6ff46eafb272d4a37b1f943adde3e1406540277a0a4f1bc18e00e124922bfVirustotal results 47.89%RaccoonStealer
2020-06-24n/aexe f09dc0b3275b4c1e3a616911805011c2871af1407599493dc980b6987cb313ebn/aAZORult
2020-06-24n/aexe 52628c4b4699682d37fc177a2d3ddfbfda54e47f31a9350756da8e4432cf6053Virustotal results 72.97% RaccoonStealer