URLhaus Database

You are currently viewing the URLhaus database entry for http://asx.sunaviat.com/data/pdf/may.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2758085
URL: http://asx.sunaviat.com/data/pdf/may.exe
URL Status:Offline
Host: asx.sunaviat.com
Date added:2024-02-07 20:01:11 UTC
Last online:2024-02-07 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Casperinous
Abuse complaint sent (?): Yes (2024-02-07 20:02:09 UTC to abuse{at}cloudflare[dot]com)
Takedown time:4 days, 22 hours, 3 minutes Bad (down since 2024-02-12 18:05:30 UTC)
Tags:dropped-by-SmokeLoader Socks5Systemz link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-02-12may.exeexe 6ca45ec9966ae895a6abd7a25a72bf3af8a8b4ab20061b90c0194b9685ce09e3n/a Socks5Systemz
2024-02-12may.exeexe 2a9cb52950ddbbaa8a9744b8be174a842e0ae5b36838fa8a4e08a8ac21ff95c3n/a Socks5Systemz
2024-02-11may.exeexe 0be71f4d68fb6c22fe0205bbfad23506090495b04b3acbe5eca97604622acfedn/a Socks5Systemz
2024-02-11may.exeexe 1574cd535d9f8195a845e096114da2e33aeb854bba43cd317340ce733f3b9ddan/a Socks5Systemz
2024-02-11may.exeexe 070fde13a0afba45eee69d58d6f709aee7d80608f31d637f480a215c1134115cn/a Socks5Systemz
2024-02-11may.exeexe 097d332f3631e239da48882e58d36d1022e72e6e7edd3072d463a10defbcf801n/a Socks5Systemz
2024-02-10may.exeexe 465bfaf248f15819b8059df957f9285b0073bf7b5e72fc683b74299a1c43efa1n/a Socks5Systemz
2024-02-10may.exeexe 108acff4d62b413c17875102e13fe62c725426bc87277fbee81a605e23300465n/a Socks5Systemz
2024-02-10may.exeexe 1cb653f5782b6fe499ca09c929bcce4b61ad328943928a7151d928a4d21a80fcn/a Socks5Systemz
2024-02-09may.exeexe 7a7e65738376b6d76523ee0401a50fae60b67fe12a2333f1466153115639e1e1n/a Socks5Systemz
2024-02-09may.exeexe 13efa1438185286baf05e6b36e742ada84be458d68c318d5fa81b3ec2c78742bn/a Socks5Systemz
2024-02-08may.exeexe 0be899f1700db62cd480904395676aaab022eb3be4ea61cc3ab9071ccbe54900n/a Socks5Systemz
2024-02-08may.exeexe 2202564a4c2feea0966c7eddf27430c836d28228575615bfba5f7345d2660949n/a Socks5Systemz
2024-02-07may.exeexe 7745f0a86461b90e7cd33dc0303235714fe069e8b62f9b8687ca04fb906ba3e8Virustotal results 14.29%Socks5Systemz