URLhaus Database

You are currently viewing the URLhaus database entry for http://levitts.ug/ac.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:414726
URL: http://levitts.ug/ac.exe
URL Status:Offline
Host: levitts.ug
Date added:2020-07-18 07:49:13 UTC
Last online:2020-07-30 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-07-18 07:50:03 UTC to abuse{at}grandcosmetic2[dot]ru)
Takedown time:12 days, 7 hours, 12 minutes Bad (down since 2020-07-30 15:02:49 UTC)
Tags:AsyncRAT link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-28n/aexe 7dad6cb83ab731da30912de41564164f65ce6cb1e81c1800358d5df6115c79b8n/a AsyncRAT
2020-07-23n/aexe 29f1643d5043e4f572f64c613b20d55aed990f165a3e27032123f358381effe2n/a 
2020-07-22n/aexe 1ddf95311b085fc2ac447335619042ce187d52031ab7e676659512fcca2cd3a1n/a AsyncRAT
2020-07-21n/aexe 41811937b0142457702e32aef8b88a0b81cff5620bbdb66b1dbc58938ea8b66en/a AsyncRAT
2020-07-20n/aexe 5fa48fe1cf1eb7b48c57e518dd5ece7c25d0ff6295cb1aab40750566a2a00c4cn/a AsyncRAT
2020-07-18n/aexe 3a730b135815ac2a4614f34cb18e94db6574c765de73db6071e1bb385d1e11b3Virustotal results 54.79%AsyncRAT