URLhaus Database

You are currently viewing the URLhaus database entry for http://zang1.almashreaq.top/_errorpages/damianozx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2728090
URL: http://zang1.almashreaq.top/_errorpages/damianozx.exe
URL Status:Offline
Host: zang1.almashreaq.top
Date added:2023-11-06 08:59:04 UTC
Last online:2023-11-06 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-11-06 09:00:14 UTC to abuse{at}cloudflare[dot]com)
Takedown time:27 days, 16 hours, 43 minutes Bad (down since 2023-12-04 01:44:08 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-12-01n/aexe 6ccdcfcad42b18c4ef436f7b0968ef7d74c974f653987806636f448497df80b2n/a AgentTesla
2023-11-29n/aexe fabea9a712e2a0ecb7c652950ff743c8d3c937fb3e24ad6c286f2c5cf6c00a45n/aAgentTesla
2023-11-29n/aexe 218a25e7be2c3d9911cfe077fde0adc5679c7a30904707322d49952c03d24d36n/aAgentTesla
2023-11-08n/aexe 30fe5b1ebaffae2df24bf63af6f57fce469643bcf5b7afe97f80ee1ccf79adbfVirustotal results 22.22% AgentTesla
2023-11-06n/aexe 5535fc7cc574af37c1d12aee3465a8c39006660bd82ca00e2b0225e6ba612841Virustotal results 36.11% AgentTesla
2023-11-06n/aexe b960c858a53c98ae2b2dc078186191048c5a8679360cb86145965fb91c98873fVirustotal results 30.56%AgentTesla
2023-11-06n/aexe 7a72be73e2bc09dd079d8aebcc617936f6e57cad6df135651ceeb504474f9521Virustotal results 37.50%AgentTesla