URLhaus Database

You are currently viewing the URLhaus database entry for http://admaris.ir/monjox/monjox.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:386642
URL: http://admaris.ir/monjox/monjox.exe
URL Status:Offline
Host: admaris.ir
Date added:2020-06-11 13:19:12 UTC
Last online:2020-11-11 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-06-11 13:20:03 UTC to mehmet{at}vitaminbilisim[dot]com)
Takedown time:5 months, 2 days, 11 hours, 15 minutes Bad (down since 2020-11-11 00:35:27 UTC)
Tags:AgentTesla link exe HawkEye link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-22n/aexe 0d24764f2fabc73cc5e74c8aac26c2e1c1cb865fe670eeeb5ea127d27bc61e90n/a 
2020-07-14n/aexe 8eebab330cd854bb3f426712bef9c2516abac5eb9ccab2f94139c0cd0dca6097n/a AgentTesla
2020-07-07n/aexe 143487bd0dd550fc5a2ba53e38b1f9afecfd9d049e051287264bfae2bfc5b47en/a 
2020-07-01n/aexe f212d0aed167593d524eaa4da68c885edcf2df200dcdb09007f0fec0e686fcd9n/a 
2020-06-27n/aexe b9302eb152029b4b0d94d7bca36c50402b8ca2f23ee13d4645b867f1e381f45bn/a 
2020-06-15n/aexe 11d10d553cdbc2b75bf849e4248e32dbadd0431f20ce25c25327c765f230b94en/a 
2020-06-12n/aexe 661c392de44d4333812c271b2e40b5a40cfb5b5fb272a89b3928f66fc3164e47n/a 
2020-06-11n/aexe 65ba735b51860a27d7b7880d4f3153ebb4817e162141ceb4624f4f10862d2cfaVirustotal results 39.44%HawkEye