URLhaus Database

You are currently viewing the URLhaus database entry for http://zmailserv19fd.world/crot777amx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:237608
URL: http://zmailserv19fd.world/crot777amx.exe
URL Status:Offline
Host: zmailserv19fd.world
Date added:2019-10-04 15:17:35 UTC
Last online:2019-10-05 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2019-10-04 15:18:03 UTC to abuse{at}combahton[dot]net)
Takedown time:1 day, 2 hours, 19 minutes Poor (down since 2019-10-05 17:37:20 UTC)
Tags:exe QuasarRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-10-05n/aexe 40377351580346622b9d5cab4e3b78fb523c6e6c31c5407fff62bdb66bfaee17n/a QuasarRAT
2019-10-05n/aexe cf77392dca0c71ce4d28f55dad3da2a4c72a6af20cb8a5b01d3de7c0f3947637n/a QuasarRAT
2019-10-05n/aexe 09d1b142f78a4c29688a8d51113e9083aa4f93472caea6ee2f6f523a12c4ce5bn/a QuasarRAT
2019-10-05n/aexe 494a88cd4ac4a973e7814b1fc77f132d97d305f228d9049ffbdd25f293af83efn/a QuasarRAT
2019-10-05n/aexe a95d850eebb01693dd276791170f97e13cf75fd4eefc07315ad35f2151defdcdn/a QuasarRAT
2019-10-05n/aexe c490e3fd77dc3a435e2c3321a21f9602042881f7f131c86e694fa9a21f3fadd0n/a 
2019-10-05n/aexe 1f93eca321004bcf2aa33833b1cc4713a5d1ef64c4c027d5d25446b220b9ee26Virustotal results 28.17% QuasarRAT
2019-10-04n/aexe 80f7014f1c9039779e3955a65c1aa7068902b44c12c644efe0a76cd3b1908420n/a 
2019-10-04n/aexe 96bd3f04b49f2c03343cc1a54daa72a90f6b775a73f969440f6d566c94ed4158n/a QuasarRAT
2019-10-04n/aexe d446d61dfab6b468318d1cc48e1f318ac16f0069368e7106699a03c701367d6en/a QuasarRAT
2019-10-04n/aexe 8b9808d4581cb503b566725b43f26dcc158b9aab4415d70b0cddfde58b8f546eVirustotal results 26.09% QuasarRAT
2019-10-04n/aexe bf108d79474a67688a250d466c9a2301b114941fb534de971ffea1d3cabcdc78Virustotal results 27.14%