URLhaus Database

You are currently viewing the URLhaus database entry for http://real.avalmag.com/data/pdf/may.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2755512
URL: http://real.avalmag.com/data/pdf/may.exe
URL Status:Offline
Host: real.avalmag.com
Date added:2024-02-02 13:01:13 UTC
Last online:2024-02-02 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Casperinous
Abuse complaint sent (?): Yes (2024-02-02 13:02:09 UTC to abuse{at}cloudflare[dot]com)
Takedown time:3 days, 2 hours, 19 minutes Bad (down since 2024-02-05 15:22:01 UTC)
Tags:dropped-by-SmokeLoader Socks5Systemz link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-02-05may.exeexe 44618efc357db6353e306ff8bcfb3e0c3dd1fb69dfc8078f1e647394a0466b71n/a 
2024-02-05may.exeexe 3cbdc920606d1de26237500736a0a2e7b751513d3bcf815f68b468ae0cc92e8fn/a Socks5Systemz
2024-02-04may.exeexe cead93a010f37896ec69252942cabe7232655f968016748ae8c8a9971b55b102n/a Socks5Systemz
2024-02-04may.exeexe 9f171c52e706b0214cd41412e2812435659ea909804c1b1ad443426bd82e1a99n/a Socks5Systemz
2024-02-04may.exeexe baabad2586eb7be9a70a88abdb18fc7cf2a20eda76192fe655d6150e4a9d6a8dn/a Socks5Systemz
2024-02-04may.exeexe b83ea47e7ca8cefec8efb014b828867332abd1a7362914dec9a449be2e01a10an/a Socks5Systemz
2024-02-03may.exeexe f4b68a4b4a90b27df4120c68473d5f58390dc2402e5b99851e3813c5b73bba87n/a Socks5Systemz
2024-02-03may.exeexe bd2c026a7f0ce17808e52812da07d31d92394682907499f9b458f35a377ad4fcn/a Socks5Systemz
2024-02-03may.exeexe 21ce025c4c170d1b07da9d70cfc7e647e7ecb13f501acf6c9aa34afc03c4827cn/aSocks5Systemz
2024-02-02may.exeexe fbc49236c45ff904ed93bcfc7df293e36953b4f14bc684ee03d447c973978a60n/a Socks5Systemz
2024-02-02may.exeexe 1f85ac615da37ae8880335354b63587cc5edc6fe787cda8425ee3a54c72f76daVirustotal results 11.11%Socks5Systemz