URLhaus Database

You are currently viewing the URLhaus database entry for http://ghostpanel.giize.com/x/5bab0b1d864615bab0b1d864b3/388_HYwcIAQXs5xdq7q.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1645287
URL: http://ghostpanel.giize.com/x/5bab0b1d864615bab0b1d864b3/388_HYwcIAQXs5xdq7q.exe
URL Status:Offline
Host: ghostpanel.giize.com
Date added:2021-09-27 08:56:12 UTC
Last online:2021-10-10 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-09-27 08:57:12 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:13 days, 9 hours, 51 minutes Bad (down since 2021-10-10 18:48:59 UTC)
Tags:AgentTesla link exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-05n/aexe 76a994f848b7bb6bb99bed1184896239219e70d0ba43c0b59e1ddd8b62827e2an/aFormbook
2021-10-05n/aexe 6b766decd906f6450f1b5812428aa61c602e0f179fe59f837fb45d5da59a30a9n/a 
2021-10-04n/aexe 32a5f96cc10d5e43cc545d6e51c8cbddf83ef67c7f0b4d55c40d5a18be6a3a8bn/a 
2021-09-28n/aexe 5559672ed11cdc40d191957be121b4f925e2119ed116e72c7349d34ece19f037n/aAgentTesla
2021-09-27n/aexe b25ef1151578640a5bb9e01fada60a8792fc4d3e92f3ddabf19ba4cd6d630f57Virustotal results 19.12%Formbook