URLhaus Database

You are currently viewing the URLhaus database entry for http://kenareh-gostare-aras.ir/wp-admin/chi.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:318907
URL: http://kenareh-gostare-aras.ir/wp-admin/chi.exe
URL Status:Offline
Host: kenareh-gostare-aras.ir
Date added:2020-02-26 07:32:10 UTC
Last online:2020-05-04 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-02-26 07:34:03 UTC to delkhosh{at}parsdata[dot]com)
Takedown time:2 months, 8 days, 13 hours, 57 minutes Bad (down since 2020-05-04 21:31:54 UTC)
Tags:AgentTesla link exe HawkEye link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-04-16n/aexe 91344ff922328efd475f36df537454997b5bf68b721e3d6daea721ac13bc1448n/a AgentTesla
2020-04-15n/aexe df7ef40378589f9428d2c85226a9bb768a280c3299584616a8f88115308c4f24n/a HawkEye
2020-04-13n/aexe 95a89c12196a013668a5acfc07ccb0e891d31881fc4d848034ee56151d6fb693n/a HawkEye
2020-03-24n/aexe 7359a9ce8cfe89dbbbb54593bdfc42eaa118b540199157fa99ea0fb11a564a92Virustotal results 16.67% HawkEye
2020-03-23n/aexe c84d0a9a9ee6556b5bb064012e81e18dd510127e531b00f995b0ace01165d15dn/aHawkEye
2020-03-23n/aexe 1d492bc6d7dd22a0ff5c75a3cff6a19629a0179b27b15045bb7893439fd91ca3Virustotal results 25.00%HawkEye
2020-03-16n/aexe 79bf4bb3e275a960f693a3b4cd8f96951da4db5dad496057f37bf4b1145b7d38Virustotal results 21.92% HawkEye
2020-03-08n/aexe 465e53740bc056a324b589f99a615220fd3d261eeda04362f13a6a011818198cn/a HawkEye
2020-03-02n/aexe 104bb4cfe6c1b9614ee6fe3e83de994cbc691e8518655edcee8f9ab0b3171f6dn/a HawkEye
2020-02-26n/aexe 2ff2a7d8e8b9d144acd23e9572114323136eda1a66156240ac43b48d00df1f07n/a