URLhaus Database

You are currently viewing the URLhaus database entry for http://cedeko.ml/zone/file/zonetor.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:899828
URL: http://cedeko.ml/zone/file/zonetor.exe
URL Status:Offline
Host: cedeko.ml
Date added:2020-12-08 18:07:18 UTC
Last online:2020-12-16 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-12-08 18:08:04 UTC to abuse{at}skb-enterprise[dot]com)
Takedown time:8 days, 2 hours, 56 minutes Bad (down since 2020-12-16 21:04:27 UTC)
Tags:bitrat link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-15n/aexe 93278752ffec8eda27f5f2694821d926dfed71cf45284c6d93ec92957becd471n/a BitRAT
2020-12-14n/aexe 59c512752d6a831fcb5b8cdb85cb718bcda9cab9fc1255f6c3528a28853e8814n/a BitRAT
2020-12-14n/aexe c326cd4d1bda4a22d81e03587d95c8c0b7f9487ed9d27bd3c5b3cb0af0a960abn/a BitRAT
2020-12-14n/aexe cdb0298b8dca0a6dd230eb6ba7cf9da0c161688f2038a643c6ef244d38716577n/a BitRAT
2020-12-13n/aexe 4ce9824eacedcaf996e12455596e623c8bd0356db6fd38caf60dcdec5ddbe4dbn/a BitRAT
2020-12-08n/aexe 9de62b6a25946e88979452c0d81b0d91e3d8e6427e9c25f11890c2aa1fe05f01Virustotal results 52.11%