URLhaus Database

You are currently viewing the URLhaus database entry for https://speedfilehost.xyz/josina.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2505213
URL: https://speedfilehost.xyz/josina.exe
URL Status:Offline
Host: speedfilehost.xyz
Date added:2023-01-12 07:17:45 UTC
Last online:2023-01-17 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-01-12 07:18:31 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:5 days, 0 hours, 38 minutes Bad (down since 2023-01-17 07:56:55 UTC)
Tags:Amadey drop-by-malware PrivateLoader

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-01-14n/aexe 94f9de1cd84edb9b60b6f24b893df57cb3943f5d80343be45b65cfe3a57ea4e5n/a
2023-01-12n/aexe 619bbbc9e9ddd1f6b7961cacb33d99c8f558499a33751b28d91085aab8cb95abVirustotal results 78.57% Amadey
2023-01-12n/aexe 429f43c832629000d3f97a08155244b7022c95d05e4c260bb68fd3e2963bef18n/a
2023-01-12n/aexe ee7bcbe03b47dc97be9ff40d314819a99dae85cfa544f726bbd59d2a4d770585Virustotal results 55.88%Amadey