URLhaus Database

You are currently viewing the URLhaus database entry for http://fresh1.ironoreprod.top/_errorpages/obizx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2737896
URL: http://fresh1.ironoreprod.top/_errorpages/obizx.exe
URL Status:Offline
Host: fresh1.ironoreprod.top
Date added:2023-12-05 20:11:07 UTC
Last online:2023-12-06 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: James_inthe_box
Abuse complaint sent (?): Yes (2023-12-06 15:23:07 UTC to abuse{at}cloudflare[dot]com)
Takedown time:20 days, 15 hours, 44 minutes Bad (down since 2023-12-26 11:56:52 UTC)
Tags:AgentTesla link Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-12-20n/aexe c39b6a89a2651948cbee31df0e5a09221c27c21027feb1b94ae99ab9fc95f513n/a 
2023-12-19n/aexe c7752e176c0a9ab287753c5e37b47c72da0eb7ae40c6c4534598c0d4fb583e79n/a 
2023-12-18n/aexe 93c052934438599045e6d9a3177f5d7d57960cad17070bc74444c1e4818bb81bn/aFormbook
2023-12-18n/aexe 7abc273fef5b3bcf3084fac4f3136a69f00fa0fc7c52e43a58dfbc5a8ae2a197n/a 
2023-12-13n/aexe 3f4c8e30cebb36371b1802267fa4f34ca434f051c90bc5f33cc654f8549d2826n/a AgentTesla
2023-12-13n/aexe 8fe077a59292dd2b43ab02a036420e9542a43c11d39086bd68019e7d40113923n/a AgentTesla
2023-12-12n/aexe cd274ae11b1d8cb63df5fc7e8140ac6bf711c3a330fd456ac14308852900ff94Virustotal results 28.79% AgentTesla
2023-12-12n/aexe a5e5a2eac636035a32e7e8750105955f0795e36715a1a46e0becba3f4a8a3672n/a AgentTesla
2023-12-12n/aexe 0b8862607850f1fb2307fdc06d90ff8f5a9665409e831c9eba545c426fd9443en/a AgentTesla
2023-12-11n/aexe 5f711f4cc8ab382941014e5694d53d753ce9b82aa9d12d3dd14c95e979f12d7bn/a AgentTesla
2023-12-07n/aexe 2214a1536f1997efda81e136d845661f0178b44a6b104f72d7f73628e6158d08Virustotal results 27.78%AgentTesla
2023-12-05n/aexe d134c531dc1702e7fb2efb1b65146a367b76cd97c78e23492f2a45719bc80a2aVirustotal results 41.67%AgentTesla