URLhaus Database

You are currently viewing the URLhaus database entry for http://lg-tv.tk/mazx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1583601
URL: http://lg-tv.tk/mazx.exe
URL Status:Offline
Host: lg-tv.tk
Date added:2021-09-01 14:47:16 UTC
Last online:2021-10-18 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-10-18 08:41:35 UTC to abuse{at}serverion[dot]com)
Takedown time:1 month, 16 days, 17 hours, 10 minutes Bad (down since 2021-10-18 09:22:27 UTC)
Tags:exe Formbook link RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-30n/aexe 41c5b0b2b9afd1f7dc207176e2a200042660dcdb02c745cc750e13f1d3ad7b01n/aFormbook
2021-09-29n/aexe e55a6e9d04d90fe3e41ce6b936bc7642dee3e7a804abfc7527ff74ee3062a1ean/aFormbook
2021-09-28n/aexe 3b012c89bb2f6a513be0335d94b0b7f8517edeb70ba37b559a94b0993df4ad80n/aFormbook
2021-09-24n/aexe 7287808b83f962ac07183a16ed4da5748e84b51946905ce0156c3b3b93ac9240Virustotal results 25.37%Formbook
2021-09-22n/aexe fcd82e581d68847a1f240bcf0123de948a8bde781a05fbbb805d0033bf91ff43n/aFormbook
2021-09-22n/aexe ce7c61720e96d0377de028d65f275d47dacfaed3cd1eb15f5080b065bde8b591Virustotal results 35.29% RedLineStealer
2021-09-16n/aexe 3b6636d54d3798272a9b5dfff832e7686f8fc9f83ccf9298c7f30ba1fc91ddd6n/a RedLineStealer
2021-09-14n/aexe c32e7fab7c0e4d5aed13b94b07fcbf1f46106000bb2388301a0a2bcbc920c757n/aFormbook
2021-09-13n/aexe 532ba22b2b3f29bce4f7a72c4d8da9c3e512840e91adb1688af8e6941107b742n/a RedLineStealer
2021-09-09n/aexe 11c58c805f392c745057848c834966d60da68935cc077206951dbde69585ac6cVirustotal results 18.18%Formbook
2021-09-08n/aexe 759cc43ff9429a9b6e48c20708461b7af39a106efbcb98d541c01d6c44ea9b3fn/aFormbook
2021-09-07n/aexe bd7323675e66df34d833d17897c6f98e9848dd062be6f299f482c09a90de4255Virustotal results 31.88%Formbook
2021-09-01n/aexe a03553c928c61ff148b7440e8dab61dc7eac554f576a35d9418f438439cc18d7Virustotal results 31.88%Formbook