URLhaus Database

You are currently viewing the URLhaus database entry for http://abass.ir/nwamaz/nwamax.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:364521
URL: http://abass.ir/nwamaz/nwamax.exe
URL Status:Offline
Host: abass.ir
Date added:2020-05-18 16:26:14 UTC
Last online:2020-07-12 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-05-18 16:28:02 UTC to noc{at}dedfiber[dot]com)
Takedown time:1 month, 25 days, 4 hours, 53 minutes Bad (down since 2020-07-12 21:21:19 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-08n/aexe d19c0492743fea479725918eaa5af205c8fde2b9e3cc6f3de6bcc7fa9f0b25a8n/a 
2020-06-30n/aexe 2df3fb91b09e4014778087cd23a2863627c1775ed1dd08c33e63168639b1d48en/a AgentTesla
2020-06-23n/aexe 4d69edbfb0ddf03fa20d939ec09c9c2b082f27d141294d2040be60fcce818eb3n/aAgentTesla
2020-06-21n/aexe 5580aa2c8da3d4a796039b22b2765616aee1976587c763f7e3a2f0c3738e8cecn/a 
2020-06-19n/aexe c408313bb998ec0599b0498f1315b30023e2d58da01c64954c912e1ea5626b08Virustotal results 44.44% AgentTesla
2020-06-08n/aexe b1221fbd695c4e5587ec5e28525d82409def861d2ee3376c28b2163e195f6b30n/a AgentTesla
2020-06-08n/aexe 83f30281a5e505534920c9b752097032706f1856ea85e75c6af492c2e8c7dd32n/aAgentTesla
2020-06-05n/aexe 3dc7611aaf0cee733ba2520adfd2087ee276ee8fdeeb6423cd99865eee458f8an/aAgentTesla
2020-06-04n/aexe 45b614dba3e415c6905f6ea8cc8346a67ed647a0aedd16a7be2a97ed644aa3c2n/a AgentTesla
2020-06-04n/aexe 96f0fae83ed3bbf72b7073d01a7b6c2637e565f892e51b308fd52664ce8b1a87n/a AgentTesla
2020-06-03n/aexe a275c124c9e69a7c6242ec32e3bf6b1c3c197c2e72f0d586b985b92dfa7675cen/a AgentTesla
2020-06-02n/aexe c677bad5164cba6393a99db3052e7fb09c3058c14897a9259611f685693c256en/aAgentTesla
2020-06-02n/aexe f3232a34ddf3d75e57216467b754d135204fddc84a1755d694aef2c4a3b599e5n/aAgentTesla
2020-06-01n/aexe 1d013fa674d82b23837c2589b833fb0410e4140ddabdb7de7e0fd1810d3810e7n/aAgentTesla
2020-05-27n/aexe 89aa23d93dbd6a5f3f4840ac1b63dc5b8f260d4eafc0dd78ae8c5254ab03638cn/aAgentTesla
2020-05-27n/aexe 9bedccb2d0f65ba4f2a15fccf825cf47e9f6d32089a68c73035787d44da40f28n/a AgentTesla
2020-05-25n/aexe 9b20ef61020a285bb6b41033eb7d188f09b1a1de002fb366d8a420a148941b86n/a AgentTesla
2020-05-22n/aexe 61a586fb831e8dfaa70ec78a1c33bb32a979dca1af2be35b369d4ee05e1b114aVirustotal results 43.84%AgentTesla
2020-05-21n/aexe 1bd2167a8fcbf887fef44678673db17761bb421b8f3b5144a2fb942d5f80ad95n/aAgentTesla
2020-05-19n/aexe 3258afd42bfcc7effe7dfefaec44bb4c10d840d4c5d225619751e44616e6615bn/a AgentTesla
2020-05-18n/aexe 18a5178de990ef6576ad3f27c3cab154b089322376d6da8921fded3ff953e70bn/aAgentTesla
2020-05-18n/aexe c4dfd4ccd5037f09039f8c86150ff684bde03e7a5a9b0be473ca9c20811710e0Virustotal results 57.53% AgentTesla