URLhaus Database

You are currently viewing the URLhaus database entry for http://luyitaw.com/okasle.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:407081
URL: http://luyitaw.com/okasle.exe
URL Status:Offline
Host: luyitaw.com
Date added:2020-07-02 13:39:05 UTC
Last online:2020-07-03 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2020-07-02 13:40:04 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com)
Takedown time:1 day, 5 hours, 52 minutes Poor (down since 2020-07-03 19:32:16 UTC)
Tags:Dridex link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-02n/aexe cc33c8c4eb3588fdd48ddb081f77040283c2f6b8c37777f8202b858b64a5952bn/a 
2020-07-02n/aexe 3d00461fa1d1f5c235f481682b5eed33d83b942936c85e61322a5e115162928cn/a 
2020-07-02n/aexe fcc0db0ce710f68915b4d73274d69bb5765012b02631bb737c66a32a9a708aabn/aDridex
2020-07-02n/aexe f365425067c9c92379df7ac5975a44e4059220e92582cdfb8c853f4a8095529an/a 
2020-07-02n/aexe c4f35b00490a1875286701b5909053c04668e4ec09da8e4ecd7405a3c136d6b0Virustotal results 24.66%Dridex
2020-07-02n/aexe cf62e1cdb2dd3f209c719e62340f61a69d442f3b391f43528c603c70ab18c8b6Virustotal results 25.35%Dridex
2020-07-02n/aexe 4160e31c01e1c9fbad1e737efb974a0cb35721023607e831292c26873bdee4dbn/aDridex
2020-07-02n/aexe 043da6ea28e1ae44078f4941c3e7db3c63566f4b312121bd3f81b6b3cec0e8d7Virustotal results 26.03%Dridex
2020-07-02n/aexe a84a6fde4dbc4575700b8be705ed1df6d576e5aa6054aa66f1fae98350484a84n/aDridex