URLhaus Database

You are currently viewing the URLhaus database entry for https://botfusion1-8f4913f37609.herokuapp.com/314904/doc2?hash=AgADBh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2726600
URL: https://botfusion1-8f4913f37609.herokuapp.com/314904/doc2?hash=AgADBh
URL Status:Offline
Host: botfusion1-8f4913f37609.herokuapp.com
Date added:2023-10-30 07:01:33 UTC
Last online:2023-10-30 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-10-30 07:02:09 UTC to abuse{at}amazonaws[dot]com)
Takedown time:3 days, 14 hours, 4 minutes Bad (down since 2023-11-02 21:06:31 UTC)
Tags:exe Sliver

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-02doc2exe b9b87cc4954c4644aaf4716e092f38fb008e37bcc781387656bf1f293d2919fen/a 
2023-11-01doc2exe 9f371f77efc1b636dc2b85681173ab66edb75287367115987d6350103e8c33c6n/a 
2023-11-01doc2exe 5e7177909f71ab7d217cf0a6ba52328d0a0ad3be543dac9e050742995c8b8d17n/a 
2023-10-30doc2exe 5da05458a8550d936109f7f15dd3e6d2a4699977a46c4bf51f3cbe19e5b6ebe9n/a 
2023-10-30doc2exe a681cf93554fb104eab53ace13b6c18c8a3bfd49774fe467b8bf18b1510405daVirustotal results 38.89%Sliver