URLhaus Database

You are currently viewing the URLhaus database entry for http://binatonezx.tk/mazx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1707272
URL: http://binatonezx.tk/mazx.exe
URL Status:Offline
Host: binatonezx.tk
Date added:2021-10-22 08:38:08 UTC
Last online:2021-11-12 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-11-11 16:47:03 UTC to abuse{at}serverion[dot]com)
Takedown time:1 month, 2 days, 17 hours, 13 minutes Bad (down since 2021-11-24 01:52:01 UTC)
Tags:exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-03n/aexe 221e9e3719749c7017ad2100a3d48e0ddb47824e02627fe859706fb591332849n/aFormbook
2021-11-03n/aexe eb1a7fdf49ef074c93385c99303fb92155f677f17c17dff1f1ad5967700d6410n/aFormbook
2021-11-02n/aexe f0b80a2a51f2e8fa5ceb014b82d25cb1fbf586c85bdd35bf0b0ab165aa7cbc3an/aFormbook
2021-11-01n/aexe 0c20d42cbdc31d5b40846425b381c84761898abe3659ba221d2b8e9e213964a2n/aFormbook
2021-10-30n/aexe 81ca6e69c74078c286b640b713714f3c8dd178bf231736919a01d653422fa5b5n/aFormbook
2021-10-29n/aexe 3cf411dfe4bd60c8bb4c7e0c77d0418c885e65570c7a5b8458d60cdf06423960n/aFormbook
2021-10-27n/aexe c4b1789371d832969f812bd0a577e380cdac00db6775d7fc251adf8d92c15d74n/aFormbook
2021-10-22n/aexe 1503a87935aa5f74d75a2ed9713fbde3faf397d99fc060155e1383b1b8e3f2f6n/a 
2021-10-22n/aexe 2486c4ebc2834ad7e9517107e7d7813fa1b84d5b2df4f928a0144b81d1273e8cn/aFormbook