URLhaus Database

You are currently viewing the URLhaus database entry for http://mashhadani.com/Library/A/key.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:5193
URL: http://mashhadani.com/Library/A/key.exe
URL Status:Offline
Host: mashhadani.com
Date added:2018-04-14 07:17:29 UTC
Last online:2018-09-08 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2018-06-11 10:45:48 UTC to abuse{at}publicdomainregistry[dot]com)
Tags:exe RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-06-22n/aexe a03b8d6e198733a5692f96653b506b507775f3acdc2ff4e62b488ab08dcbca91n/a 
2018-06-22n/aexe 3178e5a0e50c64a92e13db2e4373db6563a327155f0a5506b9df4661f5577675n/a 
2018-06-22n/aexe 19a774c9645def659f4bba9add13bf7c8bea2e871297ad46c35d5f5c68936763n/a 
2018-06-22n/aexe 1ca61bf758ce37e4f949b045d2ba4fc41b65715f7188d74e1b94296f08fd0f9cn/a 
2018-06-22n/aexe 9340fb295caf1f9ae2315b3f8556626ce6c4ea4893904c710ef8bb02ff3c4997n/a 
2018-04-15n/aexe 819ba6cd177372fee2044beb6001bf5d1ba003c541ff9e4e87c8d7939b3f4c0dVirustotal results 11.94% RemcosRAT
2018-04-14n/aexe b48af7a3d060f6764b22fc22825539b70fd3b41663fbe9e49b05cebae00c02b9Virustotal results 52.24% RemcosRAT