URLhaus Database

You are currently viewing the URLhaus database entry for http://zytrox.tk/modex/mazx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1099895
URL: http://zytrox.tk/modex/mazx.exe
URL Status:Offline
Host: zytrox.tk
Date added:2021-03-31 06:20:04 UTC
Last online:2021-04-21 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-03-31 06:21:01 UTC to abuse{at}serverion[dot]com)
Takedown time:21 days, 4 hours, 8 minutes Bad (down since 2021-04-21 10:29:01 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-04-21n/aexe 320c5b4c869e9f7905fbad7dc8d58415d105c8fc5b7d7389cc14cd62c8ebd385n/aAgentTesla
2021-04-20n/aexe 4ee91a96f4f8219145c883b6e785869dcec4a22bc98e9c95a8472fbfa2c63148n/aAgentTesla
2021-04-19n/aexe 61e6f5e7ac07ab1b9aa307b1f1feb3be8042a9440dfcdfdcfc6e710e3b0288d6n/aAgentTesla
2021-04-19n/aexe 2e727d9a26813a05ad6371ab7d4c71387dcb9b9bc99f0e23bcb52a48e3e5ea92n/aAgentTesla
2021-04-19n/aexe fda5edf4ca47ece8679d1e04e75d9af9f6ccf6510d56d2fe819f72ca09ec33d9n/aAgentTesla
2021-04-12n/aexe 776f2c4ae6ed17fe4516d3da89233b590c653c27832f6df06b2912f412eab285n/aAgentTesla
2021-04-12n/aexe 70623b6974bf44b26d80e6de5e1eb6a0e20d56d9df7b358572cb4b34b2ded73an/aAgentTesla
2021-04-12n/aexe f27364f301d24e7259772110bbb29bae3ac7956a0fcbbbf22742d16aa296ff24n/a
2021-03-31n/aexe 712c1077c77ff7e4f69fc4184c29b82b796fe0103204dd95b3a620cb64005ac8n/aAgentTesla
2021-03-31n/aexe ef2b0fcedd1f0152f46bd70df17283496544281d5ecff14b0ba81dfa2c091ac6Virustotal results 16.18%AgentTesla