URLhaus Database

You are currently viewing the URLhaus database entry for https://fresh1.ironoreprod.top/_errorpages/plugmanzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2741991
URL: https://fresh1.ironoreprod.top/_errorpages/plugmanzx.exe
URL Status:Offline
Host: fresh1.ironoreprod.top
Date added:2023-12-18 20:38:04 UTC
Last online:2023-12-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Xev
Abuse complaint sent (?): Yes (2023-12-18 21:10:22 UTC to abuse{at}cloudflare[dot]com)
Takedown time:7 days, 13 hours, 56 minutes Bad (down since 2023-12-26 11:05:49 UTC)
Tags:AgentTesla link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-12-21n/aexe 972339c3a86a22c2b15348a50e066853457dc19335262b4a8482ebbd3a39d739n/a 
2023-12-21n/aexe 28b61821d065fb29bdecfc821bfc22240b46df37ee0047cbc3cd0d9eb8b09c60n/a AgentTesla
2023-12-20n/aexe d46b48431b1613da77a297d039ad80844935b1fa40d52f1cb9b4af8e9ebea4dan/a AgentTesla
2023-12-20n/aexe c24bc032703b998d88becb9c811e9f0e389ac986cc595228d776b09689fac045n/a AgentTesla
2023-12-19n/aexe cf672b77bf6d5faee34f9ebaca90fef0222b422db31d4464ec73126a15736c3dn/aAgentTesla
2023-12-19n/aexe 4885b505604304e77da80d0d5fc1456d3feaffffccd6fbdab3f59d5be20d8a1bn/aAgentTesla
2023-12-18n/aexe 435994020a9a07105b38ca0f47bb6a362ea43f40aaa69a62121a328fa35bc322Virustotal results 40.28%AgentTesla