URLhaus Database

You are currently viewing the URLhaus database entry for http://fresh1.ironoreprod.top/_errorpages/xyoriginzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2738420
URL: http://fresh1.ironoreprod.top/_errorpages/xyoriginzx.exe
URL Status:Offline
Host: fresh1.ironoreprod.top
Date added:2023-12-07 09:40:07 UTC
Last online:2023-12-08 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-12-08 13:29:05 UTC to abuse{at}cloudflare[dot]com)
Takedown time:6 days, 14 hours, 6 minutes Bad (down since 2023-12-13 23:47:13 UTC)
Tags:32 AgentTesla link exe zgRAT

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-12-11n/aexe a50c08375ddd2954e1f0082afddecbe511c8cd55111471b34d9820f2874cdf04n/azgRAT
2023-12-11n/aexe c9b0da523668410723a6d918cd2665d644f2db3b2e4ce6eeca891c023a3eb107Virustotal results 30.56% zgRAT
2023-12-11n/aexe 8e914d4481e6f2cbe930633b63202e16c87da5851b22a64eb5ff267dec4aa9c8n/a zgRAT
2023-12-11n/aexe 481779337541e632c6908a5af824984dbce98367ac461a58d62b5470491bc8e8n/a zgRAT
2023-12-07n/aexe 246dffa57c6a16da3637457c2b4842f4d94910419be364546cb56d14b0973c9an/aAgentTesla
2023-12-07n/aexe ab4bf405f7974a896d2908640ee1e09281035911ea6760076d2cc1271afc3869Virustotal results 30.56%