URLhaus Database

You are currently viewing the URLhaus database entry for http://china.dhabigroup.top/_errorpages/plugmanzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2722095
URL: http://china.dhabigroup.top/_errorpages/plugmanzx.exe
URL Status:Offline
Host: china.dhabigroup.top
Date added:2023-10-19 04:21:06 UTC
Last online:2023-10-19 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-10-19 04:22:06 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 month, 3 days, 7 hours, 40 minutes Bad (down since 2023-11-21 12:02:25 UTC)
Tags:32 AgentTesla link exe NanoCore link RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-15n/aexe fb0808c7e819c65c6cca92d68a8efecbeef517c952a942d6075124f3fcbc08cfn/a AgentTesla
2023-11-03n/aexe b90afe6f1b6c0927ab21a826c04f4c0155dc15e8aadee54a18a08fe53a0ff7a7Virustotal results 19.44% RemcosRAT
2023-11-02n/aexe b58f87b08dad79544171f433df485d19e2f8cf9d95333292338796dc0e4b7f29n/a RemcosRAT
2023-11-01n/aexe bbf3cf4ed5267f3c9d51d83789332f041abc8b48f3889a38511d37824901955dn/a RemcosRAT
2023-11-01n/aexe 3400571ead34d9cf175d0f208823103bb3cb70097bebda17e263f255cf4c7c74n/aRemcosRAT
2023-10-30n/aexe 64efafe8721fa10c665ee811ad96f4a8f86f2d7b5c71c77418cf92657b0b3c10n/a RemcosRAT
2023-10-30n/aexe 37327eb1fc0b4ebdcc524b132cb760f5e18495832cf43b480903fd1c6cab1268n/a 
2023-10-30n/aexe f1efd86756d2b913e17e6de502d9de494ffa89b503a209f4d82d204ad1d4be6bn/aRemcosRAT
2023-10-27n/aexe 36e1db714b618d3111c93520e0acb2e96750892b90bb7a6fd3ca84e247fd380aVirustotal results 29.17% RemcosRAT
2023-10-27n/aexe 5ea4cd134199fea2a2e0716e689a4f00943f0e8a09682b21602813536b800acdn/a 
2023-10-26n/aexe d5a3a3de95ad39699281df776978e12f7fd674c563c051b44902a8ba3ca42f0bn/a RemcosRAT
2023-10-26n/aexe d3ff2d6413233eceb1cd5f1953d37a62e4fd3228dc88333d0e12f88ce465fa50n/aRemcosRAT
2023-10-24n/aexe 0f313be38c96f3b2c507291e494bb59b1db7013c8f05dd11503b39dd60e5e3b4n/a NanoCore
2023-10-24n/aexe c301ed6b1f90d3df192d237569949ea0176ed42f15690da91ab0703ae1afb586n/a NanoCore
2023-10-23n/aexe a5e23097c377fc199bdf48cb31e518bfe61b2d96d80a49d24e249970197af486n/a NanoCore
2023-10-20n/aexe cd1fb7c11680d428d1785be8cb58f1a5f941415dbd38ec36271337ae39112f53Virustotal results 27.14% NanoCore
2023-10-19n/aexe a9eead538581c0d60d2d3f5afea21fb7e6bba4e866d13d9de3e4762df25ed528Virustotal results 28.17%NanoCore
2023-10-19n/aexe 06fa859540733cee9ea3da2fc973b3a2c323e8b1e7d1d86a1fa37be6e58c55a1Virustotal results 31.94%AgentTesla