URLhaus Database

You are currently viewing the URLhaus database entry for http://paxz.tk/macdonzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1956219
URL: http://paxz.tk/macdonzx.exe
URL Status:Offline
Host: paxz.tk
Date added:2022-01-07 21:33:03 UTC
Last online:2022-01-18 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: James_inthe_box
Abuse complaint sent (?): Yes (2022-01-07 21:34:31 UTC to abuse{at}serverion[dot]com)
Takedown time:10 days, 8 hours, 43 minutes Bad (down since 2022-01-18 06:18:23 UTC)
Tags:AgentTesla link Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-14n/aexe 06c80f87ccf8d9b080ac9d8145f111738774ea48fcbc2b4d02ce25aa39dfe938n/a AgentTesla
2022-01-14n/aexe 4ca428445ec6769033f239884895359a1bc523e673b34358adb8bb326799741dn/a AgentTesla
2022-01-13n/aexe 734acbd591b35c3ab42e36ed5b97712ff3d1935a756d9158dbb1fcbaf8b5c1d6n/aAgentTesla
2022-01-13n/aexe 62bc8624b6ed645ddbe1420ca67376863c88e58e347fc8282001a2b9e3330918n/aFormbook
2022-01-12n/aexe 768d2fb5897f1f419aabfbfb7a984e07ff24f6c2261104f90d1840eed8d228dcn/a AgentTesla
2022-01-12n/aexe 466f6d4020f6617e4176b524ce43e235ee85c7a5a9c66032ddbcb7a0f9c68dfbn/aAgentTesla
2022-01-10n/aexe d29a968d9d378918cf76854c1a44226adbae7d9a4e4a47b4838d1101278284d9n/aAgentTesla
2022-01-07n/aexe d16bd368a25e14715ec80632e2cded64efd46dd4260f82922b5c64108b2d1437Virustotal results 21.54%AgentTesla