URLhaus Database

You are currently viewing the URLhaus database entry for http://abass.ir/kellyx/kellyx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:371019
URL: http://abass.ir/kellyx/kellyx.exe
URL Status:Offline
Host: abass.ir
Date added:2020-05-28 11:52:08 UTC
Last online:2020-10-23 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-05-28 11:54:02 UTC to noc{at}dedfiber[dot]com)
Takedown time:4 months, 28 days, 0 hours, 54 minutes Bad (down since 2020-10-23 12:48:13 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-17n/aexe 4ead49976f1660a17149b79d1d3bdd11b186406801d8fad5a85b8a7d1e749f67n/a AgentTesla
2020-08-17n/aexe d9680e8dba79f83eca821def0cefa1152e390b62a31fe30019a850d5617ba9a4n/a AgentTesla
2020-08-05n/aexe efe97877e848cdbb102759b9d17b35198854939d5ad4b2e05800770ae1b56c3fn/aAgentTesla
2020-07-27n/aexe 3e147cae30bff736ac9691f53fdad1f593f32e703d2051eef23303fe0ddea9dfn/a AgentTesla
2020-07-27n/aexe 064aba06cc3ce40b3bca999b47875fadacaab2aef32b6cbf1b76fdd4137d7364n/a AgentTesla
2020-06-22n/aexe 5b3314e10006b34c3b7849a01b84c4d89fbb7019fd107785f532d9275ffbcc4an/a 
2020-06-05n/aexe f0ff8cb3c17bdccf396726717ff92c0e9549de22db141873e697a191f2682828n/a 
2020-05-28n/aexe bb6ff72c412db950180fbb04fae1919c36c6d8695c3167e2d11853ade00baeb8Virustotal results 62.50%AgentTesla