URLhaus Database

You are currently viewing the URLhaus database entry for http://china.dhabigroup.top/_errorpages/owenzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2721539
URL: http://china.dhabigroup.top/_errorpages/owenzx.exe
URL Status:Offline
Host: china.dhabigroup.top
Date added:2023-10-17 06:28:06 UTC
Last online:2023-10-17 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-10-17 06:29:05 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 month, 4 days, 2 hours, 42 minutes Bad (down since 2023-11-20 09:11:47 UTC)
Tags:AgentTesla link exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-20n/aexe 5766d6d90cf61f5f2728d72d49360714ec2353a8811d695c2ebcde6efd3bbb6cVirustotal results 26.39% Formbook
2023-11-20n/aexe fa48dec8b030ce43b148cb8d250aab820e819ef39df8b3fc94852202d0d41af7n/a 
2023-11-19n/aexe 388a0c799faebfac0b16155db9e6087fcc8e9aefd56db857380acc36aa11c58dn/a Formbook
2023-11-15n/aexe 299950745849eaf8a63ec01e42013f496aa2b16d99b94122c57410e14a8844c1Virustotal results 31.94% Formbook
2023-11-03n/aexe fa53f9a0f4f52b4eb115252a9aecd5c71b6dc23588e5a16a912fe808b6bc9bb9n/a Formbook
2023-11-03n/aexe 2230b251f4acccb3ec401aa9d70e85a5dc390ba5bcf25a4f11761256d1d18016Virustotal results 26.39%Formbook
2023-11-02n/aexe 4a5be9ff6a2401e1d1d08a56acf3664ccddbae314a1d26e6debc90adb401d414n/a Formbook
2023-10-31n/aexe 87f10102a623e0a9e8f37e044736a264c8948c38685ff5d55750662010e09c5an/aFormbook
2023-10-30n/aexe 98266e6f5d23aad6132b20b3d2a9c3a0bf009eea9935fa9689e9d9ed66acf244n/a Formbook
2023-10-30n/aexe 2496fea9965443d9650f949c01e0ff191fceae80e6b8d24e91a0007791033303n/a Formbook
2023-10-26n/aexe db096d264f94a8a768c9fad0bff23e9409bbd18469e12a4b1a4b47696c0803c1Virustotal results 29.17% Formbook
2023-10-25n/aexe 6b603c9bf945295f09e43864b52c674e931e1279fb7c2f96876a7aa8cc571d4dn/a 
2023-10-25n/aexe 9bfb55b17781687c577553321bd99aee3f9ee2d02b039b1ed73c885edef3f3b5n/a 
2023-10-25n/aexe ccce32861db6de62f52dac786851efed34bb0d5f3d48130f90d8630e9e546778Virustotal results 30.56% Formbook
2023-10-24n/aexe 5b5cfb978a6740c033d1339ec75af7168870baf49efe420fb1e0c31f3651ff59n/a Formbook
2023-10-23n/aexe 2fd50e5697f2d8aa6f9bea9d946b1fbf6145aedd6cca90ee4032cbbae229e934Virustotal results 27.78% Formbook
2023-10-19n/aexe 68a24dec0cfe720af6b4691eab2b5724b156a0d6f4351157e30ffa40b9bdf4dbn/a Formbook
2023-10-17n/aexe 0b97c43d0eb22c21c8c4be37b6b45a1fd2acc9aa8c2a30012a06c2a0fb23a1f2Virustotal results 25.00%AgentTesla
2023-10-17n/aexe 9e986879ac645f058d5deb6415cc90f40130a67e3d4263be55dbe1a8ff68ad2dn/aAgentTesla