URLhaus Database

You are currently viewing the URLhaus database entry for http://zytrox.tk/modex/aguerox.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1087883
URL: http://zytrox.tk/modex/aguerox.exe
URL Status:Offline
Host: zytrox.tk
Date added:2021-03-24 09:32:05 UTC
Last online:2021-04-21 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-03-24 09:33:09 UTC to abuse{at}serverion[dot]com)
Takedown time:28 days, 0 hours, 59 minutes Bad (down since 2021-04-21 10:32:44 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-04-12n/aexe 2ae9d3570e2167f65c181acc99f212c4c9ee048d67305d22fbf20a290cc3c591n/aAgentTesla
2021-04-12n/aexe bc7b8561256da883ee46e68ee4f635d2e11a3436247ab61fa5b88455739aaf8dn/a
2021-04-08n/aexe a001fac48c0a9f6e93b9a398a90d15e2338a773891eff27145db648967ed3e5en/aAgentTesla
2021-03-31n/aexe 19949d4abee41c81c343543fc5e71de14f297440940bceb3a8f2451c7edb7d9cVirustotal results 18.84%AgentTesla
2021-03-31n/aexe 929ae3f46c76bbdd7dc0e27dc277d45b65ae1b182c35061bfd72fd063f5cc625n/a AgentTesla
2021-03-30n/aexe 4fe0cf5ea4078adae2170d820443a1a8d91d1eb6dbf886db70783998ffd65d0en/aAgentTesla
2021-03-24n/aexe ca8d2b47b68c7da2724b641ced05c71eb70b612b7fe02d9b2d89764d68b05be0n/aAgentTesla