URLhaus Database

You are currently viewing the URLhaus database entry for http://abass.ir/rawnyx/rawnyx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:364523
URL: http://abass.ir/rawnyx/rawnyx.exe
URL Status:Offline
Host: abass.ir
Date added:2020-05-18 16:30:08 UTC
Last online:2020-06-30 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-05-18 16:32:02 UTC to noc{at}dedfiber[dot]com)
Takedown time:1 month, 12 days, 16 hours, 33 minutes Bad (down since 2020-06-30 09:05:45 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-06-22n/aexe fd66b295042aee7ff6929dea2f9a937d4a41aa5921ccb8bee85df2c72f8c6574n/a 
2020-06-06n/aexe d67be73e34c8fe861c1ffb54e99af4d0549663b5381b24d4cc799663cb3b3616n/a 
2020-06-01n/aexe 0ec8fc6daa3a99def7eb952a36228ff74232291b5f6b644939a414b5a670d8c8n/a 
2020-05-19n/aexe 581a8501e44d674e94b8b9f6c4bdf5224e99ca5e042d2069809e3ff9880fc591n/a AgentTesla
2020-05-19n/aexe a6a8453fdeb8267c6b076ac3bbf7c055399b7d11cfbc1247f745c09a62a94aaen/aAgentTesla
2020-05-18n/aexe e9830074921d507af06317151a0e0132dd9a282590079de4ab45f464cf020bd4Virustotal results 54.17% AgentTesla