URLhaus Database

You are currently viewing the URLhaus database entry for http://raymondjaon.ug/ac.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:406957
URL: http://raymondjaon.ug/ac.exe
URL Status:Offline
Host: raymondjaon.ug
Date added:2020-07-02 06:13:11 UTC
Last online:2020-07-08 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-07-02 06:14:03 UTC to abuse{at}grandcosmetic2[dot]ru)
Takedown time:6 days, 5 hours, 51 minutes Bad (down since 2020-07-08 12:05:14 UTC)
Tags:AsyncRAT link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-06n/aexe 88a7fddcf06a6de22db25ffaaebe30826f9c12cde87724e61a53e49e19e3651bn/a AsyncRAT
2020-07-05n/aexe 9ce03e27501dd7aee72d30a74c0ee87b8f692bb02bb4f4c6c4a0f320cb989c2dVirustotal results 16.44% AsyncRAT
2020-07-03n/aexe 47120315dad770af7a3fe09a4e245e6cb4984b4f31f2649c82f7b290f2ed3f0an/a AsyncRAT
2020-07-02n/aexe ad883970a2ffd6e5830f051cc5fdde3a688c0c24810ed3faba7379dd170496b8Virustotal results 28.77%AsyncRAT
2020-07-02n/aexe 5eb283456bc3e36b0e9b03e7ff168ee6c9b7e75dd056cff392d9fc101a8dbe0aVirustotal results 17.81%AsyncRAT