URLhaus Database

You are currently viewing the URLhaus database entry for http://china.dhabigroup.top/_errorpages/pablozx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2726784
URL: http://china.dhabigroup.top/_errorpages/pablozx.exe
URL Status:Offline
Host: china.dhabigroup.top
Date added:2023-10-31 07:17:05 UTC
Last online:2023-10-31 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-10-31 07:18:06 UTC to abuse{at}cloudflare[dot]com)
Takedown time:21 days, 20 hours, 37 minutes Bad (down since 2023-11-22 03:55:35 UTC)
Tags:exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-16n/aexe 76e4a5e23c32d448a6718887f2cdc8fba3d37b7907ab50e962917a7abd58f5c9n/a Formbook
2023-11-16n/aexe c58ee1f431830de9ebef623d97434e4e9d44bc5071acf79cca34cae18f8bd6d9Virustotal results 23.61% Formbook
2023-11-14n/aexe 8285c8cd3f4e1c196aff1a4ad35cb620d39cb2c10291e8c450c7e768ff246e9cn/a Formbook
2023-11-14n/aexe e44c8c6ac40d66dd3d0ea95552196390759b2df6b9a762f37124688f760794a5Virustotal results 37.50% Formbook
2023-11-14n/aexe 95145c771434dd825809d958daafceaa22ab64c014b3cef802616bb659f339acVirustotal results 19.44% Formbook
2023-11-10n/aexe 3c5af02b843a0fd2df2f8558917ab584aa45de1ee6ab13612d589fd8c653bbf9n/aFormbook
2023-11-10n/aexe cf1280dea0bfb86e585e302b4dc4fd51cb1f12847b4685cd377f1a6c8f63765bn/aFormbook
2023-11-09n/aexe 04073b41e1f33312946b820420b0ec47883fed34fe5b6db261bfd0b99feb0a91n/aFormbook
2023-11-07n/aexe 9680fcf70fd9253914ccf18d134c357b91fbce01f3f5161d13d54f0ddd464872n/a Formbook
2023-11-03n/aexe f6f98abf837a049522d544e95eaa09569bba0f8e0ec25db653f5e51ad1023455Virustotal results 33.33% Formbook
2023-11-03n/aexe 024aa4a117fa7c5952577b1e904510e09c0e048a7bfaf320fcbdb4f309c41ba5n/aFormbook
2023-11-02n/aexe d05f9af8ab2a4f8d284f8c55ff0d6bd49148f110d19dee193fafdd8a132b5c6bn/a Formbook
2023-11-01n/aexe c6e6a23c715a82063d1b291988942a7ba040e1e5238b2f46ea8fb6a6744ec0bcVirustotal results 36.11% Formbook
2023-10-31n/aexe ee15b6d592e19dac7b1baedfd072befcf7351c2e65ca5b2fca9ed1fb61ba3e11Virustotal results 18.75%Formbook
2023-10-31n/aexe 042f89b9396cad4393609eb2a2acd29260f9d8b48734e31344ec6ffd890599d6Virustotal results 31.94% Formbook