URLhaus Database

You are currently viewing the URLhaus database entry for https://date-flash.com/temp.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1381699
URL: https://date-flash.com/temp.exe
URL Status:Offline
Host: date-flash.com
Date added:2021-06-20 07:32:10 UTC
Last online:2021-11-14 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-06-20 07:33:02 UTC to ipnoc{at}techavenue[dot]net)
Takedown time:4 months, 26 days, 23 hours, 59 minutes Bad (down since 2021-11-14 07:32:32 UTC)
Tags:CobaltStrike link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-14n/aexe 5781fd1c6b3917e6de3875016bb24cd37c75b282281b4feaedef78a524e85fcen/aCobaltStrike
2021-09-20n/aexe 6cc8e13f66166e615a847f9444a0258b0e7a01fb8e607c49c482b2b4d50cd829n/aCobaltStrike
2021-08-31n/aexe e292bf04e0c03341436ab4411ddde881129db4904ae2234952f3a655f14d5cb7n/aCobaltStrike
2021-08-24n/aexe 97353134cb9688dda31e50d288370079161ac91ed800de8bba629ba0c6040834n/aCobaltStrike
2021-08-23n/aexe 4e9cee63c296120b3640a6201b4cb4295be8cfec39a4828eb4c4fc34d69cc69cn/aCobaltStrike
2021-08-22n/aexe 8d084f5dde01196806d96122f6e76321cc1fdd0fe97fbf3606e5ab4e54ccb0e3n/aCobaltStrike
2021-07-26n/aexe b735bf8a33209f968ae46a4f632bc07bff6ea83f66130934365b5be363657fd4n/aCobaltStrike
2021-06-20n/aexe 984265f2a1df743a585b3ed1aa138080dbc0e27c66d2472d10a66c916739556cVirustotal results 60.87%CobaltStrike