URLhaus Database

You are currently viewing the URLhaus database entry for http://www.evograph.ro/js/fw1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:850939
URL: http://www.evograph.ro/js/fw1.exe
URL Status:Offline
Host: www.evograph.ro
Date added:2020-11-24 21:19:05 UTC
Last online:2020-12-02 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-11-24 21:20:22 UTC to abuse{at}nshost[dot]ro)
Takedown time:7 days, 22 hours, 30 minutes Bad (down since 2020-12-02 19:51:19 UTC)
Tags:ArkeiStealer link exe RaccoonStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-02n/aexe 9a91c5db492dc2a2acad21ec201c9598d49e76dfec9ca89fef1624cb34c95bdcVirustotal results 28.17%RaccoonStealer
2020-11-29n/aexe 025e6f24f86484bb2ffd57d222a4e0e18c43b43cd0209100fb780d67c3be893fn/aArkeiStealer
2020-11-28n/aexe 48dd07930ff57b6eed433487810ca1adb757cb49166ea5037440364290a69874n/aArkeiStealer
2020-11-27n/aexe 92426fe39cddb0d10510d1a6d2d90600b651b55cdf7f441782b9b3ad7817f935n/aArkeiStealer
2020-11-27n/aexe 4626980a591b50826c7ed3ba55812df592c8abd7e40131438d4faa0319aac7fbn/aArkeiStealer
2020-11-26n/aexe c6054f12d81d13377e8236ed3c9f891c0a456529d6bb91a541afbe9f4e1c2738n/a ArkeiStealer
2020-11-25n/aexe 754d057252e7b4584a67240267b76200b74c6945d23f9f2301a8b1ba4215fac6n/a ArkeiStealer
2020-11-24n/aexe 44ff6d294f2a5bd347385b204d5d6e219ce5e785cf567fb48820b0c4aefac4e1Virustotal results 59.15%ArkeiStealer