URLhaus Database

You are currently viewing the URLhaus database entry for http://admaris.ir/ahihix/ahihix.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:386938
URL: http://admaris.ir/ahihix/ahihix.exe
URL Status:Offline
Host: admaris.ir
Date added:2020-06-11 15:40:16 UTC
Last online:2020-11-11 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-06-11 15:40:18 UTC to abuse{at}selectel[dot]ru)
Takedown time:5 months, 2 days, 8 hours, 58 minutes Bad (down since 2020-11-11 00:38:29 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-28n/aexe 3d4daa07c1f49aa2dfcb027208f538fd947d1dda536275d4045c5fb6e9cc2791n/a 
2020-07-22n/aexe c865ae6451002cac5a2e06f4ec36e1eea806b6dccd37fb88175df0ae8d98d049n/a 
2020-07-18n/aexe c567d2ab3fbaf91c815577d89e9c6547ed14652534b1728273f9c6300c869711n/a 
2020-07-07n/aexe f44631ad506ed325224ef11de6abde757acf8a895bc46ec061422e09c597fdddn/a 
2020-07-01n/aexe e66f442b2f21d93b3019abb230f697d3d088b914a1e9c95fbbd0e502e7b972cbn/a 
2020-06-30n/aexe 91533ed69b418dbffc9c79089b1fa375c9a6282ce5b6a20fed96fd4a9dba9c24n/a AgentTesla
2020-06-23n/aexe d23143c08dadac0a9421456456e6b86934fcde6833dedd9461a9b1ec111e1931n/aAgentTesla
2020-06-22n/aexe a4f8af29a7cc20593c44db22452ce9c351ada8c6ad0e759b69e4381c4e4895afn/a AgentTesla
2020-06-21n/aexe 7e6b52b9f6cb1db7189e24d43ff500fd2e9985f3f4b7ba93ef1f4079af16979cn/aAgentTesla
2020-06-17n/aexe 699f82ad6cf617803183dad7a8aaf28562665ba9dcd20952c588b9e3d3c18248n/aAgentTesla
2020-06-16n/aexe 952bcbf4d87174e764a821482a63022c616fe159ed9a72ed44d4b6f81b091f0cVirustotal results 34.25%AgentTesla
2020-06-15n/aexe 27acf46938632a2dce525dcb8a6e131473bf2d54066de1fd68ee49558547c434n/aAgentTesla
2020-06-12n/aexe 9704baea17754bbf1de8f944e4a1b0d0f2868c165acb6678e7253541c4c6af48Virustotal results 32.88%AgentTesla
2020-06-11n/aexe a6d3d0a36c6e679431d7ab9c3cc258c41be5fbb8569d9ad698b4b7ba140665cdVirustotal results 45.95%AgentTesla