URLhaus Database

You are currently viewing the URLhaus database entry for http://uzoclouds.eu/arinze/arinze.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:326255
URL: http://uzoclouds.eu/arinze/arinze.exe
URL Status:Offline
Host: uzoclouds.eu
Date added:2020-03-18 06:19:27 UTC
Last online:2020-03-23 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-03-18 06:20:03 UTC to noc{at}dedfiber[dot]com)
Takedown time:5 days, 6 hours, 28 minutes Bad (down since 2020-03-23 12:48:48 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-03-23n/aexe b0acab0b38a67a7841b6f2aa1e9c3c8a5d65dfb245faf3ce9f12bd57f146d29dn/a AgentTesla
2020-03-20n/aexe 230f6fdc192980c8816f25dc6c86b15748e48f23ae14650791ae3e87d3eedeadn/a AgentTesla
2020-03-19n/aexe 9a976ed46419dfb9e1d81ac4756fb9288fc98f241d50d0185db776d5f21cbe23n/a AgentTesla
2020-03-18n/aexe efab5691427df802977f9170761420d10f6ebec2dd878ebd6e00d3e6bcc3b141n/aAgentTesla
2020-03-18n/aexe 446e55249a19fcefa746b41fc9ca16bf38c7e876b8334e46b92f53133269d78fVirustotal results 36.11% AgentTesla