URLhaus Database

You are currently viewing the URLhaus database entry for https://cdn1.frocdn.ch/eCVXk3pYsYhZNlI.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2716277
URL: https://cdn1.frocdn.ch/eCVXk3pYsYhZNlI.exe
URL Status:Offline
Host: cdn1.frocdn.ch
Date added:2023-10-04 03:55:06 UTC
Last online:2023-10-05 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: stealerkiller
Abuse complaint sent (?): Yes (2023-10-04 05:45:08 UTC to abuse{at}advinservers[dot]com)
Takedown time:23 hours, 51 minutes Good (down since 2023-10-05 05:36:59 UTC)
Tags:AgentTesla link exe infostealer stealer trojan

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-10-05n/aexe f9a6b7c9bbccae7a2bfd4ec6b3a1555314981f8c56bdcdb70842fb67183340d4n/a 
2023-10-05n/aexe 2977dd84def6dfe64f37cb8cf87a296125ba19899424cf0c784117c64bbde0c5n/a 
2023-10-05n/aexe a96733dd7a61d1ec431264d221d09dcd53e84706e9b525d91c88cdb2228be179n/a 
2023-10-04n/aexe b31acd770b750caecaf13392978b7ff96907c346ee307b474514725ac1e4249bn/a 
2023-10-04n/aexe bacfce630c06766a1c54b55395b84232dfb01a99844a0c732fa45470d9bd434bVirustotal results 62.50%AgentTesla