URLhaus Database

You are currently viewing the URLhaus database entry for http://bigshottoken.io/wp-includes/css/lev/origajo.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2398510
URL: http://bigshottoken.io/wp-includes/css/lev/origajo.exe
URL Status:Offline
Host: bigshottoken.io
Date added:2022-11-03 01:45:12 UTC
Last online:2022-12-28 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-11-03 01:46:14 UTC to abuse{at}inmotionhosting[dot]com)
Takedown time:1 month, 25 days, 9 hours, 22 minutes Bad (down since 2022-12-28 11:08:15 UTC)
Tags:32 AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-12-08n/ajs 59322be3598f3f670a6ab23cf9918356698b42278b451d4853eae70241cfa583n/a 
2022-12-08n/ajs 74e096f64fc9201ffda7589f022d6fb02a15199c5d8de5bb26a4ab0534ba3429n/a 
2022-12-07n/ajs f276401fbed8d00d4e25b1d1a3181dcd6a4f0061d218715748a326530a53b893n/a
2022-12-02n/ajs c603b6417f5a98239f3730d9c38e365cd95746864f60934b5d95eef4eee8eef5n/a 
2022-12-02n/ajs efc90c48ca8073bb00b67155db0b597a2bab80181cc3c923cc437b328d227566n/a 
2022-11-17n/ajs 70ea5819150fdde7721bbe1a52c11883efa0f77d13c7e576ead9524d4919b2cdn/a 
2022-11-03n/aexe f6affd72ae56e2fde50c5c451638940d4089f0e37064fb9bfef5de2d8ae2b924Virustotal results 45.83%AgentTesla