URLhaus Database

You are currently viewing the URLhaus database entry for http://twart.myfirewall.org/taskmgrs.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1143865
URL: http://twart.myfirewall.org/taskmgrs.exe
URL Status:Offline
Host: twart.myfirewall.org
Date added:2021-04-20 10:57:07 UTC
Last online:2021-04-26 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Malware domain
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-04-20 10:58:04 UTC to abuse{at}amazonaws[dot]com)
Takedown time:6 days, 0 hours, 38 minutes Bad (down since 2021-04-26 11:36:26 UTC)
Tags:AgentTesla link exe NanoCore link rat Xpertrat

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-04-26n/aexe 698d686ce288fb2943f7587b30d1dfa01f0ba1f5e3de8be766770ee98f945acfn/aNanoCore
2021-04-26n/aexe f8e52fa75724eb08c0ec68db6799740ad36c7178b8f0dd7c8b0ee755ff60c653n/aXpertRAT
2021-04-23n/aexe 0b85c64339f4fb161e5fe4972ebf6832f06969f3f5f05dbfd636c75bf61ea432Virustotal results 31.88%NanoCore
2021-04-22n/aexe 877b28707372fb7365c52a314233c74877045cf1d8143fe83fb257f0bf90c248n/aXpertRAT
2021-04-21n/aexe 7aa6ba1ed3e72514eac19d8b9ee4f95a17e33b63159bc75bd57ad8b38ce6361en/aXpertRAT
2021-04-21n/aexe 3f2ce17fe342c19e6ac9890f379841df3c448099e6565b9906538b463fc02932n/aAgentTesla
2021-04-20n/aexe 8a5feb638a86eef3e912827fab799130ab284c72275c74bfd8449c10ab41ff2fVirustotal results 14.71%NanoCore
2021-04-20n/aexe fc8d2060f52b693d1745bac54a0943292519d643917590d4ded54a9cbd96ea7aVirustotal results 29.41%NanoCore