URLhaus Database

You are currently viewing the URLhaus database entry for https://appxoxo.com/upload/drive.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2800996
URL: https://appxoxo.com/upload/drive.exe
URL Status:Offline
Host: appxoxo.com
Date added:2024-04-04 09:21:36 UTC
Last online:2024-04-05 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-04-05 03:30:17 UTC to abuse{at}simplecarrier[dot]net)
Takedown time:1 day, 0 hours, 22 minutes Poor (down since 2024-04-05 09:51:48 UTC)
Tags:dropped-by-PrivateLoader meduza

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-04-05n/aexe 43b9b71ba6767fda9748590734a94d570fa2553f8f056ca60e8d96a925de30e4Virustotal results 20.83%Meduza
2024-04-05n/aexe fb1454d4d93e03243d5b4529e65f0580a07e30fb2446fa59efe652eb253adb30n/a Meduza
2024-04-04n/aexe 60fc51853ecb5cdf78c1a4e1fdec264405168baac8f8c422206b40dd5e47afdan/a 
2024-04-04n/aexe 0f8b8e294577598a477970e3e2ac5b5a1bda0b90aacb61eca90b2b1cb80a119dVirustotal results 12.50%Meduza