URLhaus Database

You are currently viewing the URLhaus database entry for http://china.dhabigroup.top/_errorpages/maxziflowzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2735875
URL: http://china.dhabigroup.top/_errorpages/maxziflowzx.exe
URL Status:Offline
Host: china.dhabigroup.top
Date added:2023-11-28 03:48:06 UTC
Last online:2023-11-28 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-11-28 03:49:06 UTC to abuse{at}cloudflare[dot]com)
Takedown time:9 days, 14 hours, 24 minutes Bad (down since 2023-12-07 18:13:17 UTC)
Tags:32 exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-12-07n/aexe f96ec7b8deb20a1f569aa97ca83cb01d3d547f56e0113f7d4f6d81ac2457bfb1n/aFormbook
2023-12-06n/aexe a400163ff05373a5b8f7d0eb5e2b3efebbde782cafb1b4bd167aaa6cc2b4e9d9n/aFormbook
2023-12-06n/aexe c5f627e96016f33374d51c988a8a5c41072cc03ed73adcaf19dee2853976d50fn/aFormbook
2023-12-05n/aexe 7f50e41f876ba8fcb2aba2ef12bc48a5378363a60d3b5dada11ffee027de9879Virustotal results 27.78% Formbook
2023-12-05n/aexe de75b43745c380f3ff5aadcc1b8c12869d0905377d903b868638360f16f8acffn/a Formbook
2023-12-04n/aexe d149fc6adc07ffa848eb414438af0bb68cee6b0f3d7c4fe5dc919e7f5182bd27Virustotal results 28.99%Formbook
2023-12-04n/aexe a3e976c5f8b9e3039d059d5ff191e101184cbe57659e26adeac329de319b7d0bn/a Formbook
2023-12-01n/aexe 974ea2be86b0522eb455956d1efb56e665907b0ee2b0bdd7b08d71d139b5d264n/a Formbook
2023-12-01n/aexe 117b1e683c1f3cd129ade43fa0d4d9ec92e47439d67eb489d4dc3efc3138c0d0n/a Formbook
2023-11-30n/aexe 699e987cabfc7a0a4856a7e57bc9ed2f94a6b993e885cfc45e423e923ca1b59aVirustotal results 29.17% Formbook
2023-11-29n/aexe 9ac3ba328288fab79fddb47315bd24a8d9e7b9b99b03df042fdc03aee20202abVirustotal results 29.23% Formbook
2023-11-29n/aexe 0fa32bd9031ce39788bc74912def8e1c2c7bb82de8976ee94d2d15fd4c890355Virustotal results 27.78% Formbook
2023-11-28n/aexe 499b9aba5bbcc6a66bc341089f9cf3debf205fc2ac3c9ee85862f395bc9eed66Virustotal results 27.78%Formbook