URLhaus Database

You are currently viewing the URLhaus database entry for http://abass.ir/bobbyx/bobbyx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:365985
URL: http://abass.ir/bobbyx/bobbyx.exe
URL Status:Offline
Host: abass.ir
Date added:2020-05-21 07:41:21 UTC
Last online:2020-10-23 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-05-21 07:42:02 UTC to noc{at}dedfiber[dot]com)
Takedown time:5 months, 5 days, 5 hours, 18 minutes Bad (down since 2020-10-23 13:00:30 UTC)
Tags:AgentTesla link AZORult link exe Loki link lucifer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-14n/aexe 9ba42d773ffbfa3355cf1c1ac206d7cab460749057a5884044cb7b162dd22d29n/a AZORult
2020-09-07n/aexe 7e3789d445792dbe592a626e5a352d3cd0f52b55620324c8c0e692ebcae412f0n/aAZORult
2020-09-07n/aexe 1b110d92119feeca030ea1cbcf9b90781829330374d74c6740ecfa8e645b9a87n/aAZORult
2020-09-07n/aexe 8e6b5cfd9dd4931b8b847caa458b755ab2cf7dac6793ea2be22e6a111e3cca4an/aAZORult
2020-09-07n/aexe a0ac0b34898186c8e9400fe4e2fa71a228b455a9fce6d9261fe3c9d062d028f5n/aAZORult
2020-07-08n/aexe 6eb1e94df113e574eacf15e6ba6dfee8469365e1c42f0870db2e0b72337678ecn/a 
2020-07-08n/aexe e590780453fe7e2f70cf0b337452505e33c7a3f81e0694e7391a515990078c26n/a 
2020-06-22n/aexe 732447bf9865490fb739e33cf2723768a39163c0d00a158b22265c60534d0372n/a 
2020-06-09n/aexe 7b4e1a97692d88780ecf0e45d128a307287fb1fd705ebe494640487da7d13391n/a 
2020-06-07n/aexe 37fee2b23406c332d47b0f88b8b79479bf07e5764b5f671a84106c4313fcddd8n/a 
2020-06-02n/aexe a1bf146c35c74c629420c6c093d43181a53c8ae787cfb1b6d45318e3c02746d3n/aAgentTesla
2020-06-01n/aexe 6a6207b2c3f01fa407688c123560d04cffc63322cd9a4a1248a47b389075a373n/a 
2020-05-27n/aexe 6689bb01faa4b79ccbf36e24360b14f2ee181d2bf305b7ca59fd275109e92dc1n/aLucifer
2020-05-21n/aexe dd829409e00a1dc3a74c8c6ecfc826fbd9af89ea4b8438021ea2ce7b4d602a5bVirustotal results 68.06% Loki