URLhaus Database

You are currently viewing the URLhaus database entry for http://www.zhuoxinwei.com/work.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1012890
URL: http://www.zhuoxinwei.com/work.exe
URL Status:Offline
Host: www.zhuoxinwei.com
Date added:2021-02-16 14:06:07 UTC
Last online:2021-02-26 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-02-16 14:08:07 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com,abuse{at}12321[dot]cn,abuse{at}alibaba-inc[dot]com)
Takedown time:9 days, 15 hours, 11 minutes Bad (down since 2021-02-26 05:19:08 UTC)
Tags:AveMariaRAT link exe njRAT link rat

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-02-17n/aexe 94bfa8c9f21aecceb10954cefcfb8089a87f213d5642bfd9f9b3b20c4d35c80dn/a
2021-02-17n/aexe e37938245442bf4c1114da250f93cb5cc2fea5c35e50883b819f3c8afc4ab363n/anjrat
2021-02-17n/aexe caf2426860f30acfd54896fffbbd9c0287aea7f7dc5e51ead591381aedcd31d4n/aAveMariaRAT
2021-02-17n/aexe a2f25508bf1afda77068376b2ff8418e18a089bf2dfa31df58bf3428eb8b5477n/aAveMariaRAT
2021-02-17n/aexe da2f28066626c5233467f5cffeba4c770bb1e2d4a0ab70d11dde42051ab4a547n/anjrat
2021-02-17n/aexe 48b29379fd85a693a02194e85bc1e465bbe75215d24d2a7d564dedbe31b02aedn/anjrat
2021-02-16n/aexe 34931da71c14d251f6a43f21ef98c4b67bf17535d7164f154bc6206625363140n/anjrat