URLhaus Database

You are currently viewing the URLhaus database entry for http://cassiagumrefined.com/js/file/TH98/86HTe.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:348813
URL: http://cassiagumrefined.com/js/file/TH98/86HTe.exe
URL Status:Offline
Host: cassiagumrefined.com
Date added:2020-04-23 12:22:09 UTC
Last online:2020-05-02 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: oppimaniac
Abuse complaint sent (?): Yes (2020-04-23 12:24:04 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:8 days, 23 hours, 56 minutes Bad (down since 2020-05-02 12:20:10 UTC)
Tags:exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-04-29n/aexe a574b201fa1b1b05d857cff48993efd19a3f700c55d6a7ea8ea9a1da30becb62n/aFormbook
2020-04-28n/aexe 55cf5e68816fcdbf38c5c1b306e3fc3d1dae18b8a578b714a3bc23d728c2ef33n/aFormbook
2020-04-28n/aexe 36cf15c7906183eac126f2943a83b58c9d97292cb09040291084e09cdde0152cn/a Formbook
2020-04-27n/aexe 569b8cf6219a91161d48291f13285babe58b3be185623f3ec44c65c8369c2278n/aFormBook
2020-04-27n/aexe ef14e580eca50b75acae60fa7c6642fa89fc91ee8492f5193608937f4d78781bn/aFormBook
2020-04-26n/aexe 1fe0526a4c4014b9a986dd3265ee007a4009f2491530a83113848184e25a1fb0n/a FormBook
2020-04-25n/aexe ee5d24692f47eb58ccd302e280a422a91eed36199622e25befe80765568dc8f9n/a FormBook
2020-04-25n/aexe 1e9ce0d6760bfc646d3ebfe2c2bf4ff35ac84bf622f8fbd734568d38db7cbb33Virustotal results 26.39% FormBook
2020-04-24n/aexe 95d5f321ec85b0584ede72123e9709b3c74f6125b1ea08b0357c5ef8d9b37b81n/a 
2020-04-23n/aexe 8c9611ab9a8a8dbc44f93e6f81cb2c46ed936cdde7fb88b9410d50bde750cfb6Virustotal results 5.63%