URLhaus Database

You are currently viewing the URLhaus database entry for https://api.ezilax.com/client/better.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3612734
URL: https://api.ezilax.com/client/better.exe
URL Status:flame Online (spreading malware for 9 months, 3 days, 3 hours, 50 minutes)
Host: api.ezilax.com
Date added:2025-08-27 18:02:14 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: burger
Abuse complaint sent (?): Yes (2026-03-01 07:34:16 UTC to abuse{at}cloudflare[dot]com)
Tags:exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-26better.exeexe 2045f583c1c8163fc9d69a9eca0c1dfa2dd8b9c08f1acbbad1b6bc03f80bcdc1n/a 
2026-02-25better.exeexe 71aca2e0583b81b3b843e54724b928eacbd18b7cde9d361b97fa9f28024253b7n/a
2025-10-25better.exeexe 05060a3336aaa6badc9db2d0fd131712862e8935f2353fe4d1c1bb6b1bb9023dn/a 
2025-08-27better.exeexe 2c24acac4391202f1deaca85213116b702d7f7163d36ba41bfd248e867343fa4Virustotal results 26.39%