URLhaus Database

You are currently viewing the URLhaus database entry for http://china.dhabigroup.top/_errorpages/sbin22zx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2724617
URL: http://china.dhabigroup.top/_errorpages/sbin22zx.exe
URL Status:Offline
Host: china.dhabigroup.top
Date added:2023-10-24 05:53:04 UTC
Last online:2023-10-24 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-10-24 06:51:06 UTC to abuse{at}cloudflare[dot]com)
Takedown time:21 days, 18 hours, 35 minutes Bad (down since 2023-11-15 01:26:57 UTC)
Tags:exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-10-30n/aexe 398d4c9bea813210e56da3547fc784f0ffee56f99bb8f95216d05c7d06a14d63n/a Formbook
2023-10-30n/aexe 3ae3c2764b8897a7a39488b9b3be4c6dd65ae259e77f9893d8e78e2e91292153n/a Formbook
2023-10-30n/aexe 3ac037f29c08bafccd3cf6c0e88cb933795ea25bf1e9415ed89e83574b7f2566n/aFormbook
2023-10-24n/aexe eb2c77eb03b17cdb76301d30bf4b07d97f3d0a742d198cf84a191c8271a42b4aVirustotal results 44.44%Formbook