URLhaus Database

You are currently viewing the URLhaus database entry for http://abass.ir/dutchx/dutchx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:384201
URL: http://abass.ir/dutchx/dutchx.exe
URL Status:Offline
Host: abass.ir
Date added:2020-06-08 22:52:10 UTC
Last online:2020-10-23 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: p5yb34m
Abuse complaint sent (?): Yes (2020-06-08 22:54:02 UTC to mehmet{at}vitaminbilisim[dot]com)
Takedown time:4 months, 16 days, 14 hours, 11 minutes Bad (down since 2020-10-23 13:05:28 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-07n/aexe b5584b15ea2b8c09efd59f8ddb16a380076a4bc2dc85c545810b26de0b795958n/a AgentTesla
2020-07-31n/aexe 1c9d77531fafcb6b976656bea2a0e647688a049499956979b6d121640c6b29abn/aAgentTesla
2020-07-27n/aexe 7b7e9529e03ad79217be486e5c133c5e676d0442d242a11e1107a3e0e84c7dc4n/a AgentTesla
2020-07-27n/aexe cb52ed2f196b63ad9288404a3f1cbb587ad9a3b84d863a6672de235a3ec851b5n/a AgentTesla
2020-07-07n/aexe 9faba87b124e5eb46fde1fd028c7c9fac55f936b2436b15ea9bebe09782f2a3bn/a 
2020-06-08n/aexe b696bd66d67df6095b792c081f3c3f71f5fe29f58b5cd8599e0fd5e1f16d290eVirustotal results 76.06%AgentTesla