URLhaus Database

You are currently viewing the URLhaus database entry for http://zang1.almashreaq.top/_errorpages/millianozx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2728026
URL: http://zang1.almashreaq.top/_errorpages/millianozx.exe
URL Status:Offline
Host: zang1.almashreaq.top
Date added:2023-11-05 19:17:07 UTC
Last online:2023-11-05 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-11-05 19:18:06 UTC to abuse{at}cloudflare[dot]com)
Takedown time:10 days, 2 hours, 22 minutes Bad (down since 2023-11-15 21:40:06 UTC)
Tags:32 exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-13n/aexe 5fbe64657d05cbbba18f255662e902d7b519e6b1eca0610a518c4031f828130fn/a Formbook
2023-11-13n/aexe b3a50f27f037fc524303604335c490550752f7eb426553a73b12b8ada3d2f892n/aFormbook
2023-11-13n/aexe 68a36aaf1639ea16df035f8d02db1861718af75420c3be35cec42958e33834c8n/aFormbook
2023-11-10n/aexe 4d21d3cbfee58a117f7586d46351dc3d02cc8bfe0042ee4135ee03332d1257feVirustotal results 30.56% Formbook
2023-11-10n/aexe 69198ac34f842ce3b024f60b27eee21661924b5f492983016cb3fed070702248n/a Formbook
2023-11-09n/aexe da49519a5670d282de449cee9f55bfdfb034d4fd011e7420152ed3e841a00372n/aFormbook
2023-11-05n/aexe 5669840788d19dbb20f845d3beffd4ba401886023cb434fc944ad8c2c002b84cVirustotal results 69.44%Formbook