URLhaus Database

You are currently viewing the URLhaus database entry for http://abass.ir/userclientz/userclientz.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:362025
URL: http://abass.ir/userclientz/userclientz.exe
URL Status:Offline
Host: abass.ir
Date added:2020-05-13 10:59:39 UTC
Last online:2020-07-12 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-05-13 11:00:03 UTC to abuse{at}Iranianwebman[dot]ir)
Takedown time:2 months, 0 days, 10 hours, 21 minutes Bad (down since 2020-07-12 21:21:56 UTC)
Tags:exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-08n/aexe bceba0dc1538af47ed3c84fb41adff097b3a57d8f7a5a0ce2df3286d3a6a5813n/a 
2020-06-26n/aexe f3e4e24a9090575c9633a273ef70cb88a4faf7c040c70041030d839f28583073n/a 
2020-06-26n/aexe d3f9fdd3cdccda4aa0f9d1b57897135fa4ccc43365f3b4ab74ee83fdfa45bf89n/a 
2020-06-21n/aexe 24ecdcf440a62ad52d7278d18d6cf6286d0d950c21a190e8eb2228967f7f4304n/a 
2020-06-02n/aexe 7d3dafb317dcb8d2bde2ada39f2c7a75ddf1ec53af9720c860667553a022951bn/a 
2020-05-14n/aexe 1589c05dfc5d8d25d7e959e05dc7b34ff4c82406cf48b21dd008de8364a745ddn/aFormBook
2020-05-13n/aexe ba3486ddcb815a5bfae81495f4f48576968b3d6de9f42e0d4358824d7ee583bdVirustotal results 38.89%Formbook