URLhaus Database

You are currently viewing the URLhaus database entry for http://admindepartment.ir/templx/temple%20file%20cripted.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:386534
URL: http://admindepartment.ir/templx/temple%20file%20cripted.exe
URL Status:Offline
Host: admindepartment.ir
Date added:2020-06-11 07:53:09 UTC
Last online:2020-11-11 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-06-11 07:54:02 UTC to mehmet{at}vitaminbilisim[dot]com)
Takedown time:5 months, 2 days, 16 hours, 25 minutes Bad (down since 2020-11-11 00:19:09 UTC)
Tags:exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-07n/aexe 092ab9d8086a125fb0362e4195e8f04d704b5d131d7bb9db46c78f74014f8eean/a 
2020-07-22n/aexe af5ec8b1c6e8d0760ada3f5eae6d4589e3293b85621b5123b1878d7b0237f78bn/a 
2020-07-19n/aexe 69a5341c07873d2ac0c735341a5214e0b0715cf9f6e089181910c8be0a3892b5n/a 
2020-07-05n/aexe 56daf95631cdc32e71f0dc34625562588e05f3f3147950208529ce4f14592e32n/a 
2020-07-04n/aexe c7feb6ee21897155ada00a5f63de6dcb8ff7127b8e5cc1a0aeee80f6b5fb14ecn/a 
2020-06-22n/aexe 6f441e450f924c3c0d4c04b6b0099341d52c3ba7709d3e457fcc8f80e05dd0e1n/a 
2020-06-11n/aexe 532b875f09991cdf7b57db59f0f7aa579d49b229d65ad1ace9f67bf6ffc7bca5Virustotal results 26.39%FormBook