URLhaus Database

You are currently viewing the URLhaus database entry for http://peak-tv.tk/damianozx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1989711
URL: http://peak-tv.tk/damianozx.exe
URL Status:Offline
Host: peak-tv.tk
Date added:2022-01-19 15:22:05 UTC
Last online:2022-02-23 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: James_inthe_box
Abuse complaint sent (?): Yes (2022-01-19 15:24:34 UTC to abuse{at}serverion[dot]com)
Takedown time:1 month, 4 days, 16 hours, 32 minutes Bad (down since 2022-02-23 07:57:06 UTC)
Tags:AgentTesla link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-25n/aexe 84abe78d773f55b54649a4dfefaa61461211fd7eb03338c984f8458ad695b1fcn/a AgentTesla
2022-01-25n/aexe 88b348808c427343e33d222946c1a5ed210c13abc7ed7388072b10282551c0a9n/aAgentTesla
2022-01-25n/aexe a83af43286bd8f2f1872ed354365f2ce2cad246291efc239f6ddc4e9f3a2fa18n/a 
2022-01-21n/aexe 7162329049ef9e88afaa46525dabed19ed2f6d1a619c6ad09880bef3971d30ben/aAgentTesla
2022-01-20n/aexe 485e2bc6495b81a1a80138ca932975c685a89d2a4f52e2da3ddd911698a5de79n/aAgentTesla
2022-01-20n/aexe f687b7b49c0e1a404fcb75f1519afe90b2777be63611de9e95d37e4f41c62a37n/aAgentTesla
2022-01-19n/aexe c3ba8ff4689b7b8c502fb09e64f88ae3395125fe4ec6f9e0d9a6dd80b328839fVirustotal results 39.39%AgentTesla