URLhaus Database

You are currently viewing the URLhaus database entry for http://china.dhabigroup.top/_errorpages/zackzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2736248
URL: http://china.dhabigroup.top/_errorpages/zackzx.exe
URL Status:Offline
Host: china.dhabigroup.top
Date added:2023-11-29 14:33:03 UTC
Last online:2023-12-15 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: James_inthe_box
Abuse complaint sent (?): Yes (2023-12-15 06:25:09 UTC to abuse{at}cloudflare[dot]com)
Takedown time:20 days, 10 hours, 48 minutes Bad (down since 2023-12-20 01:36:34 UTC)
Tags:AgentTesla link Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-12-14n/aexe 61c11d170ceb320bafd7872824de7ce33d10fdbb5ef585e67487f9afcde5e207n/a Formbook
2023-12-14n/aexe 6e1354e8f98dc8491e30fcd2e64638874ff4d6c521e158a7495b78dd802a2850n/a 
2023-12-14n/aexe add05b10b13891172810c8f90bf624f892ad69fed993944491736cc283a31b01n/aAgentTesla
2023-12-04n/aexe 56b45823ca44e1959238432a9da3365844e8e416f79127f94eb0926d3ccc422dn/a Formbook
2023-12-04n/aexe d76f0bd5be27187672f2b89be93eba20033cadb397398143bfe6f81d8ef4d9ddVirustotal results 25.42%Formbook
2023-12-04n/aexe 529eadbbbabaf043158e40ec137e40f33c818f9eacd89dfdbc844f574ee85766n/a Formbook
2023-12-03n/aexe 6bf7843d672f60dc32a986a9db555c78e31b38f4b70d4e0af687e9e0a69fa8f8Virustotal results 28.57%AgentTesla
2023-11-29n/aexe a8149ed051ce39e0fd94eb4f6af6934cc9e5860242aec44c3ea3a36454af69dfVirustotal results 41.67%Formbook