URLhaus Database

You are currently viewing the URLhaus database entry for http://www.frcomex.com.br/pdf/wpx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1910882
URL: http://www.frcomex.com.br/pdf/wpx.exe
URL Status:Offline
Host: www.frcomex.com.br
Date added:2021-12-22 14:19:11 UTC
Last online:2022-01-10 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-12-22 14:50:24 UTC to abuse{at}ovh[dot]net)
Takedown time:1 month, 17 days, 11 hours, 25 minutes Bad (down since 2022-02-08 01:46:45 UTC)
Tags:32 AgentTesla link AveMariaRAT link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-28n/aexe 19a49c9cb9da2bc3b2118a642a80937c4250e754c3773bf87b6ee557593ce75cn/a AveMariaRAT
2022-01-26n/aexe 475557cf6b3350281115e918b51953c55b5e06ecb815f4dcb682cceb0c096389n/a AveMariaRAT
2022-01-25n/aexe 4be36802d451c0339a624086b90b07248e15d5b97119326ecc403202c4ce9363n/a AveMariaRAT
2022-01-20n/aexe 626c607438b9b8d16dc84c0610a9ad73f7831358078d37de63f5778a6c2a2411n/aAveMariaRAT
2022-01-19n/aexe 229a02b7daf1a8531508d2cea0b8496286c011e56453a48485928f3c853528a3Virustotal results 36.23%AveMariaRAT
2022-01-17n/aexe f10f6f1b92d0498bb45ff22ae0d3c9337afc67f17484d17a17a4c95bada4fd90n/aAveMariaRAT
2022-01-13n/aexe 9011683087e75b6729c3aa410f6263f856999a08e76f82beceebdfdd51e098e3n/aAveMariaRAT
2022-01-10n/aexe acb8bbe441cb61ad58a298b9d7460c88caf003cae9e2e8762530a999aa65eec9n/a AveMariaRAT
2022-01-07n/aexe 677ea3bde24fd6ccb8945d584eab801c52309dd46f98b2ea6f433e173379c91aVirustotal results 14.93%AveMariaRAT
2022-01-06n/aexe 9ef2af9dab98d55dc0305406b2c900f0043b13155866fc6a8189d30ec6046e28n/aAveMariaRAT
2022-01-05n/aexe f46c908b3e728a16ee971d886207c0288dd82e6528b7b6a18b48d1e5a565ca74n/aAveMariaRAT
2022-01-03n/aexe 1ba55192b1d0898473aafea254c6962e98f7b87c9ed5cf3a6ef071810268fff1n/a AveMariaRAT
2022-01-03n/aexe f23d02cdf53583b863b2df8235ed3042c8206529863c02c2ea1d79dcd5a35a4an/a AveMariaRAT
2021-12-23n/aexe b86cb703d96588a972e3a44c2800e48c1a6140329a035b5d3aa91c8f741109f8n/aAgentTesla
2021-12-23n/aexe ea1edfa1df970d123a6f2898e24dde94edf4f136908c41419a20190a575fc624n/a 
2021-12-22n/aexe 7d29ff32379efd3a3ee28d4204ebf7515025b86a4bdd7bd59a577ef1f6c9a2baVirustotal results 19.64%AgentTesla