URLhaus Database

You are currently viewing the URLhaus database entry for http://zmailserv19fd.world/socks777amx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:237606
URL: http://zmailserv19fd.world/socks777amx.exe
URL Status:Offline
Host: zmailserv19fd.world
Date added:2019-10-04 15:17:16 UTC
Last online:2019-10-05 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2019-10-04 15:18:03 UTC to abuse{at}combahton[dot]net)
Takedown time:1 day, 2 hours, 19 minutes Poor (down since 2019-10-05 17:37:19 UTC)
Tags:exe Gozi link MedusaHTTP link PredatorStealer link QuasarRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-10-05n/aexe e14cc1f5ed18efe5f247d4c0585aca63ad128314fbe3817711deff52ec986ab9n/a QuasarRAT
2019-10-05n/aexe 30fcbedeed62d22dd7c7053a1aee5454ba3d14229b4447e05c597b19755a7342n/a 
2019-10-05n/aexe 4b50886c6ea3f44e4870448d1e0fe1b167c2c620add7167e0b7e086d07da3f06n/a MedusaHTTP
2019-10-05n/aexe 076d4ffbc3e790fddcbb4a1101bc259d63bb3a7c664e3ac31e6a2b29c7707ef7n/a MedusaHTTP
2019-10-05n/aexe a66fb3137f5a82a0f4bab5e73d336be299f0d13221bb8c3d7121f7061ec8ffc8n/a PredatorStealer
2019-10-05n/aexe 751660c10b048586a98b23641066e20807229397ce078377a1a542cc5f85ff93n/a 
2019-10-04n/aexe 73d72f3f846957303bf01ee2bb7bbcbf1b13d905ccaa1105dd4b97f2969fd9f7n/a Gozi
2019-10-04n/aexe 605d585f9bf3af300ca48c65618931f8a6405b211287ad6ebc7a0148bc9be1ddn/a 
2019-10-04n/aexe 086d73e9d5850fb831169c9473edbad9f1c989ed66373479eb565fedee5059e6n/a MedusaHTTP