URLhaus Database

You are currently viewing the URLhaus database entry for http://fresh1.ironoreprod.top/_errorpages/damianozx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2722011
URL: http://fresh1.ironoreprod.top/_errorpages/damianozx.exe
URL Status:Offline
Host: fresh1.ironoreprod.top
Date added:2023-10-18 16:29:04 UTC
Last online:2023-11-27 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-11-27 16:20:09 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 month, 11 days, 6 hours, 52 minutes Bad (down since 2023-11-28 23:51:12 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-27n/aexe 3f171b3ce9feb8ee0327ff88a4a197e7e0d00c67cf0892c890f06e9d641ecf45n/a AgentTesla
2023-11-16n/aexe 154bd8b2f86010c2a6a61cb770231b2b21b2ef88c6893ca146ec2fc7a65632e3n/a AgentTesla
2023-11-16n/aexe d5b15d40c4de18d1ec6dbcd643a30ea9d7f33e1520aa7a1b2f30a29afdcaa99cn/a AgentTesla
2023-11-16n/aexe 30fe5b1ebaffae2df24bf63af6f57fce469643bcf5b7afe97f80ee1ccf79adbfVirustotal results 70.83% AgentTesla
2023-11-06n/aexe 5535fc7cc574af37c1d12aee3465a8c39006660bd82ca00e2b0225e6ba612841n/a AgentTesla
2023-11-06n/aexe 7a72be73e2bc09dd079d8aebcc617936f6e57cad6df135651ceeb504474f9521n/aAgentTesla
2023-10-29n/aexe 3d9b12a4b382e5c767c0ba1f020fd5948e9a91def03248d5fe10f31edb44f225n/a AgentTesla
2023-10-27n/aexe 9b27a40ac362fc0d3b27564c77e21ee210af95681c38b1db381a2fe395e3948bn/a AgentTesla
2023-10-26n/aexe 2994d5d9965778bf6d739ad76f95c3a9cb13775490e19fdda9e21634cd5f538bn/aAgentTesla
2023-10-26n/aexe 87730724acb6bcf3e167072ae649750b6ba40514ab450338082a4b9cd00b2935Virustotal results 27.78% AgentTesla
2023-10-23n/aexe 3b2c93cd586d420389e91c343deeccd11fcea4d55d615614ffd908049425973en/a AgentTesla
2023-10-23n/aexe 4ff8a522ef000b82d57dfa14f4e9b04967e4240dc36a0c7c3e0c53834afcf0c5Virustotal results 80.28%AgentTesla
2023-10-18n/aexe 08bef6d15fe30410b624cfad64ba2e410312d8bb03fa602a31b69c91dd307147Virustotal results 31.94%AgentTesla