URLhaus Database

You are currently viewing the URLhaus database entry for http://china.dhabigroup.top/_errorpages/whesilozx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2727987
URL: http://china.dhabigroup.top/_errorpages/whesilozx.exe
URL Status:Offline
Host: china.dhabigroup.top
Date added:2023-11-05 16:58:05 UTC
Last online:2023-11-05 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-11-05 16:59:05 UTC to abuse{at}cloudflare[dot]com)
Takedown time:21 days, 9 hours, 2 minutes Bad (down since 2023-11-27 02:01:10 UTC)
Tags:32 AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-17n/aexe 263cb87efba7c1368587c1f9736ae1a7ad5459387792908804cd689cd23ea524n/a AgentTesla
2023-11-17n/aexe 9f9dc522c56f9e71ddfecfdc2a19a1a3a5d724a3f4df7b52e9847b30e1f82ae7n/a AgentTesla
2023-11-17n/aexe df6ca890b6c57b7e3a86b4d2849583c98e5c581ef14e37755bd272c0a2ec3368Virustotal results 20.83% AgentTesla
2023-11-16n/aexe 0ebb771a41e09281b2fe6cbbc666322ef9aa305f47630023233c25f3a7bcb0a4Virustotal results 27.42% AgentTesla
2023-11-16n/aexe 3c3bf9a0945640f328c0a80e253543cda6783b6f81b22c8ab0008245ea6dd0aan/a AgentTesla
2023-11-15n/aexe 2913e01bf2825250ed3c5db236dcce19b01aacafe04afe100d2ca775a7fbe383n/a AgentTesla
2023-11-15n/aexe 0e751a5bcc53c0fc4ca2387de9f813655a2d3363ca65da546eab18f19125b20cn/a AgentTesla
2023-11-14n/aexe 36eb41b722d13b7055cde745205b7765b831bbeef2c434d5b7d4c82c614bd5can/a AgentTesla
2023-11-14n/aexe 233163f77cb5c00725d585c1f2eb804b3e762aa62d522fcf3931abe2dd14fd40n/a AgentTesla
2023-11-13n/aexe 33e42ae8f0660868df640a57434592fd834ce5680e923f345929ae8d92f9209fn/a AgentTesla
2023-11-13n/aexe e9676f9f6eb075c838b3d574aaa1c3be8a59449d1ee54eec7b73308bfe5047c6n/a AgentTesla
2023-11-10n/aexe 5ff913a048669356b6caa413a7d7cca106ede598be29b9c51204677044f57d44n/aAgentTesla
2023-11-09n/aexe 57f754eba9d66d89bf2cf7a0e16e75efbee776272e1f1d43a66b0542b8b9c843n/a AgentTesla
2023-11-09n/aexe 10aef4b7f07631e404687b889f409fe604cb2d78ae832f65e7c8a17dcb7544e7n/aAgentTesla
2023-11-05n/aexe 074b0928569d0bd3f56a9075e9dd562f6b6da76bde6187dc65eddbc4050f2eacVirustotal results 52.78%AgentTesla