URLhaus Database

You are currently viewing the URLhaus database entry for http://abass.ir/ycmb/ycmb.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:362028
URL: http://abass.ir/ycmb/ycmb.exe
URL Status:Offline
Host: abass.ir
Date added:2020-05-13 11:14:06 UTC
Last online:2020-06-22 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-05-13 11:16:02 UTC to abuse{at}Iranianwebman[dot]ir)
Takedown time:1 month, 9 days, 23 hours, 54 minutes Bad (down since 2020-06-22 11:10:05 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-06-02n/aexe 62005a4721dc55f0752df55ca79bd85ccb46ba28a34d10d8f29880e087b69896n/aAgentTesla
2020-06-02n/aexe 2007e26236724b66614306253b3d2c5ba4721762d796dcd56720f0e65faaab4fn/a AgentTesla
2020-06-02n/aexe 0cd9fd5b00bc80998230045add39993d63c2846570cebacc6a5c72ec63e88a92n/a 
2020-05-26n/aexe 9463f129f4dec7224eb12c262e080ffa58c104bde38104319ab69d2fdb8919een/aAgentTesla
2020-05-20n/aexe 7607102eead4fb3d71ed2c2b492eb4828d5c544576102aaa94d29debce0f211dn/aAgentTesla
2020-05-18n/aexe b9ec899a1cb59794313ed0db3e338dbc43970785be52cf756b0d33588c0064d8n/aAgentTesla
2020-05-15n/aexe 746ba131d45c2cb05eaaf9081877f7fba2887d1369d8e4867f17898b45a1f3b3n/a 
2020-05-15n/aexe f4272e700fb10073ab711bc495f0d8780cc9bfed1afb94c97ffe4ed35195d141n/a 
2020-05-13n/aexe eced8139c7651d297e4bc18c9b8783b76ffa477c07e09b269739d8b6fa0d14deVirustotal results 54.29%AgentTesla