URLhaus Database

You are currently viewing the URLhaus database entry for http://andreas.ac.ug/ds2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:439791
URL: http://andreas.ac.ug/ds2.exe
URL Status:Offline
Host: andreas.ac.ug
Date added:2020-08-24 14:21:06 UTC
Last online:2020-12-08 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-08-24 14:22:03 UTC to abuse{at}grandcosmetic2[dot]ru)
Takedown time:3 months, 15 days, 17 hours, 7 minutes Bad (down since 2020-12-08 07:29:05 UTC)
Tags:exe MassLogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-07n/aexe dcad9f659dc4eba1e24a19a68661e64aee4c4ba1e9465fab91535c3db50dfe5an/a
2020-11-29n/aexe 42381fda66b581117e935a929786ec81ddb50bb88a827ac3960810305e07b853n/a 
2020-11-18n/aexe 463ca08ac1072947eaa864e2f94e3703b1e9826543e194be0b45e2aa20331872n/a
2020-11-10n/aexe 8f00b0da22ad089cc4f9e26d98d4f2000ea0cba3add268d471be4f027c1a965cn/a
2020-10-28n/aexe ec96689bd6797689fbba3fa9e9278f2c9f9810f6cc9e5536ae47dd2139e0893bn/a
2020-10-26n/aexe 3005d49fd313fedcf242a6ba2c6ffc962ce86469fe1bce77f775e64457f7ea33n/a
2020-10-14n/aexe 3bed0900c2ba2423e8b4882ef157f017a4f84068bd1f5721c0a7567a13cbb66dn/a
2020-10-13n/aexe 3d37c3617a157667f9e536996ce1f4e790060b8b8449f905bf9c1f5bcd09b7a9Virustotal results 31.43%MassLogger
2020-08-25n/aexe 9d8bc1654854fa5d8b42322cf91999e37225a25a6acf06dcc8c918571ab3d932n/a 
2020-08-24n/aexe 9f20023fc4c5c192804b85d3d206b9b78cbce88746d8611a69d27f40228d1f0aVirustotal results 73.91%