URLhaus Database

You are currently viewing the URLhaus database entry for http://fresh1.ironoreprod.top/_errorpages/chungzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2722669
URL: http://fresh1.ironoreprod.top/_errorpages/chungzx.exe
URL Status:Offline
Host: fresh1.ironoreprod.top
Date added:2023-10-20 11:55:17 UTC
Last online:2023-11-30 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-11-30 12:16:07 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 months, 7 days, 0 hours, 30 minutes Bad (down since 2023-12-26 12:26:41 UTC)
Tags:AgentTesla link exe rat RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-12-21n/aexe 8645e36eb1542409a86fca23f57dfc5d56aeffa19c4a1c8d94a97e5310762107n/aRemcosRAT
2023-12-21n/aexe 24ecb80587bb9a508578d701c54a7e8ead6d4800fdf806175b5445f8178c4511n/a RemcosRAT
2023-12-19n/aexe d02530a2bac21b47a1ecaafc185ddb11680c9a90d0fcb2c52b7b081b952f1cd2Virustotal results 45.07%AgentTesla
2023-12-03n/aexe 5fc47bba076e30759ef93078ae0a5aa3748004c80c8d00eb3fc789eb58853affn/aRemcosRAT
2023-12-01n/aexe 1b70413c8570742f5966cf6c4bc87902d154048412c01debd08eb4467b5534dcn/a RemcosRAT
2023-12-01n/aexe ef7927d67d1dac8ad59e4166fbbe9a61da10635247187714bdba605937106665n/aAgentTesla
2023-12-01n/aexe 7f448e7539ef2dcc167a97bb2744c12d8d412fb0eda46cea638d452070c70d4an/aAgentTesla
2023-11-29n/aexe ba5c976cdb12e69be0720611b892224357fcd036fa86fcc503aeaf9a08d13952n/a 
2023-11-29n/aexe fb6e5a6a4b210daa7b622e1a95fc1b85fbdabc32a288c74fe331be78f91f82a2n/a RemcosRAT
2023-10-20n/aexe 015de283d33b7b246204fad78eaede87ab7939aaa34f035d59569aec3606747dVirustotal results 61.97%RemcosRAT