URLhaus Database

You are currently viewing the URLhaus database entry for http://zsdstat14tp.world/socks777amx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:237833
URL: http://zsdstat14tp.world/socks777amx.exe
URL Status:Offline
Host: zsdstat14tp.world
Date added:2019-10-05 05:59:17 UTC
Last online:2019-10-05 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: JayTHL
Abuse complaint sent (?): Yes (2019-10-05 06:00:03 UTC to report{at}abuse[dot]bz)
Takedown time:11 hours, 37 minutes Good (down since 2019-10-05 17:37:16 UTC)
Tags:MedusaHTTP link PredatorStealer link QuasarRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-10-05n/aexe e14cc1f5ed18efe5f247d4c0585aca63ad128314fbe3817711deff52ec986ab9n/a QuasarRAT
2019-10-05n/aexe 30fcbedeed62d22dd7c7053a1aee5454ba3d14229b4447e05c597b19755a7342n/a 
2019-10-05n/aexe 4b50886c6ea3f44e4870448d1e0fe1b167c2c620add7167e0b7e086d07da3f06n/a MedusaHTTP
2019-10-05n/aexe 076d4ffbc3e790fddcbb4a1101bc259d63bb3a7c664e3ac31e6a2b29c7707ef7n/a MedusaHTTP
2019-10-05n/aexe a66fb3137f5a82a0f4bab5e73d336be299f0d13221bb8c3d7121f7061ec8ffc8n/a PredatorStealer
2019-10-05n/aexe 751660c10b048586a98b23641066e20807229397ce078377a1a542cc5f85ff93Virustotal results 28.99% 
2019-10-05n/aexe 8acbe9804f7c47ddd5e28bccd1d2a9ee57c9f9098eb182b4dc78a3633cb0e35fn/a PredatorStealer