URLhaus Database

You are currently viewing the URLhaus database entry for http://secretpath.xyz/japele.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:415965
URL: http://secretpath.xyz/japele.exe
URL Status:Offline
Host: secretpath.xyz
Date added:2020-07-21 11:14:10 UTC
Last online:2020-07-22 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-07-21 11:16:02 UTC to abuse{at}selectel[dot]ru)
Takedown time:22 hours, 57 minutes Good (down since 2020-07-22 10:13:24 UTC)
Tags:Dridex link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-21n/aexe ba07c4c584e73c14357101fe0d9d201f69d160b4c878433a02584ee666e5d15fVirustotal results 33.80%Dridex
2020-07-21n/aexe 908b559a8329911ef44e734150d2ba19b1cb0c44c486cb9090fcfb8e89cb7565Virustotal results 35.62% 
2020-07-21n/aexe f14c036ec4b5e6ba025cd6e9b7a7af410619338faed8d40c1b2116b8faa7e043Virustotal results 32.39% 
2020-07-21n/aexe 0a3cf0144537bec43eedf67790270668a4b646665e0f7a0993786cfdb50db7ddVirustotal results 30.00% 
2020-07-21n/aexe 3e929bb0e5736933931825285c6ae5040a6b080dd361507b2f677e5f51576288Virustotal results 30.43% 
2020-07-21n/aexe 00940314e879a63955b70dff5d8d843ac0395e60560acb1f69dd80fbd765a144Virustotal results 32.39% 
2020-07-21n/aexe 4a8429e12437ff33866dfbcdc31059e69ffd1e1f15bf3e76d49564050484b3eeVirustotal results 30.99%Dridex