Scan report · about 10 hours agoPublic

aberraofficial.com

209.145.54.87AS40021 · US

Suspicious: page delivers an executable (https://aberraofficial.…9uPKcqQjZ32eLTRpPb.exe)

document pretext ("docusign"); execution instructions ("downloads folder")
Engine tags
Verdict

What happened

Step by step, from what the scanner recorded.
Load 9.3 s · 2 requests
01 · Visitor opensaberraofficial.com
02 · Page shown
Secure Document Download
03 · File delivered · maliciousNew-Inventory-Summary-fleetdeck-agent-DQyw9uPKcqQjZ32eLTRpPb.exeaberraofficial.comHanded over by the page, not served at the scanned address.
04 · OutcomeA program on the machineAn executable or installer was handed to the visitor under a pretext.

Dangerous — confirmed threat

Confirmed

It is listed on external threat-intelligence feeds. The file it serves was analysed and found malicious. We found strong evidence that this site is malicious — for example a phishing page, a scam, or hostile code. Treat anything it asked for (passwords, card details, codes) as exposed.

What to do

Do not enter any information or download anything. If you already did, change those passwords now and contact your bank if payment details were involved. Block or report the link to your team.

This reflects the evidence found at the time of the scan. If you believe it is a mistake, you can escalate it for analyst review.

Findings

Strongest first
MalwareMalware found in the downloaded file
New-Inventory-Summary-fleetdeck-agent-DQyw9uPKcqQjZ32eLTRpPb.exe

We analysed the file this page delivered — it is Malicious.

Success

SHA-256 550e6ec6ca473cd7063a8014f57ff91267592a68717a51bf85899cc660c6a5ec

SupportingPage delivers an executable under a document pretext
https://aberraofficial.com/rest/New-Inventory-Summary-fleetdeck-agent-DQyw9uPKcqQjZ32eLTRpPb.exe · document pretext ("docusign"); execution instructions ("downloads folder")

The page presents itself as a document but its button downloads a program to run, not a document to read.

Analyst noteConfirm what the download actually serves. A document workflow that delivers an installer is the tell; the file itself may be signed and clean.

File

Stored by the engine

What you download may be live malware. Open it only in an isolated environment, and do not double-click it.

The ZIP is encrypted. Password:infected

Inside the ZIP the file carries a name the engine generated, not the one the page used.

Delivered fileMaliciousNew-Inventory-Summary-fleetdeck-agent-DQyw9uPKcqQjZ32eLTRpPb.exe

SHA-256550e6ec6ca473cd7063a8014f57ff91267592a68717a51bf85899cc660c6a5ec

Fromhxxps://aberraofficial[.]com/rest/New-Inventory-Summary-fleetdeck-agent-DQyw9uPKcqQjZ32eLTRpPb[.]exe

Infrastructure

IP
209.145.54.87CONTABO-40021 - Contabo Inc., US · AS40021US
TLS
CN=YR1, O=Let's Encrypt, C=US · expires Dec 28, 2026
Redirects
0 hops · / → /

WHOIS

Registrar
NameCheap, Inc.
Created
Oct 7, 2025
Expires
Oct 7, 2026
Nameservers
dns1.registrar-servers.comdns2.registrar-servers.com
36 malicious18 suspicious

Hashes & fingerprints

Analyst reviewMalicious· about 9 hours ago

Analyst indicators

RMM

Reviewed by—

Page capture

Live

Title “Secure Document Download”

Engines

8 · time to verdict

Page

HTTP
200 · Completed
Title
Secure Document Download
Load
9.29 s · 2 requests
Stack · 2HSTSNginx