URLhaus Database

You are currently viewing the URLhaus database entry for http://irequestyoutopleaseadviseonthepayment.duckdns.org/explore.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:362270
URL: http://irequestyoutopleaseadviseonthepayment.duckdns.org/explore.exe
URL Status:Offline
Host: irequestyoutopleaseadviseonthepayment.duckdns.org
Date added:2020-05-13 20:34:09 UTC
Last online:2020-07-02 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-05-13 20:36:02 UTC to abuse{at}colocrossing[dot]com)
Takedown time:1 month, 19 days, 11 hours, 41 minutes Bad (down since 2020-07-02 08:17:28 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-01n/aexe 7ee2faf4b7b906e3d8b33dadfe33324d19905991a0eed7079cd0d7ae06bec049n/a AgentTesla
2020-06-24n/aexe 2db853eacff3513f7c3b63f8fa58baa6f4eb2a8cb6d1b6d60ec62c85b3bc8801n/aAgentTesla
2020-06-24n/aexe 36d66adb4896b0206b98cccb59cb536a1243e23446d82c462a846ece5d436532Virustotal results 23.29%AgentTesla
2020-06-16n/aexe 6f1dc48e03263b206dba0b4f14c2346c0738f64f3665adf0d144166855806eabn/aAgentTesla
2020-06-10n/aexe ab89da90c3c7146e0aeeb484e0118ef6a555a9d65c1f04324527b1286d672804n/a 
2020-06-02n/aexe f04a05489b8b264acb58fcbe7303a326496636009062bbf0025cfe08f4a7ce07n/a AgentTesla
2020-05-29n/aexe ece2dc66da65eef81ed0334f693af9d614858075ade048120b02cefc89c216b0n/aAgentTesla
2020-05-21n/aexe f937a030aa7da32b23e2df28ce632e2f3aa1ec02c67c93fbaae247c139b64727n/aAgentTesla
2020-05-13n/aexe 3505dc04f65f639a619e14e5ab8903e08bd4a83890cb99a336ae17557d419ec8Virustotal results 29.17% AgentTesla