URLhaus Database

You are currently viewing the URLhaus database entry for http://hdmilg.xyz/mazx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1538943
URL: http://hdmilg.xyz/mazx.exe
URL Status:Offline
Host: hdmilg.xyz
Date added:2021-08-16 12:23:07 UTC
Last online:2021-08-30 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-08-16 12:24:05 UTC to abuse{at}serverion[dot]com)
Takedown time:13 days, 13 hours, 40 minutes Bad (down since 2021-08-30 02:04:12 UTC)
Tags:exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-08-24n/aexe 11dde0ea97b2f63edbd9d6b42af105bff7fad9225396219a6de96cb8d51125d7n/aFormbook
2021-08-24n/aexe df19a60152fff0338d5ee7d2b969a4dbded6d3f2752ae246090e7e8f79c43815n/aFormbook
2021-08-23n/aexe 70d759be9f935d289ee1627038a118e9493d45ecebfcd477f0b43a8253afffb4n/aFormbook
2021-08-23n/aexe c27adae0af4b3c5c71d33f4707fc1e0c51cd9ed61f88169014a6022fabc87dc8n/aFormbook
2021-08-20n/aexe 0aa68b819455d1810d114c502d6a221d0da9320d506c31b9e83b7a488f46a954n/aFormbook
2021-08-20n/aexe 3f8cd22d1b3b93b4884c70e6a9c032d2d7e2bb341db8ea85d4c86b1d0e5cfaf9n/aFormbook
2021-08-19n/aexe 6cbc8098614c094caf34a0eae5242f77ae55e6ff77184f6a5b708703698ccc1an/aFormbook
2021-08-18n/aexe 39e1002eaf485405155f98f77b331263ab1e6fea26623dd83029f9bcc58d3c9fn/aFormbook
2021-08-17n/aexe 73c2ee6d691663df62c983da3572abc381a0940f2cbdfb2ed8d48cb225d7b5f9n/aFormbook
2021-08-17n/aexe cc9460866fbf6ae7430f759bc11a90a3536a0032319f20757421a2e08f60faban/aFormbook
2021-08-16n/aexe 35a776da3e6d2d8bcd69a7427ab25846c233403372bf3ecb6055c252ae696766Virustotal results 34.78%Formbook