URLhaus Database

You are currently viewing the URLhaus database entry for http://admindepartment.ir/arinze/arinzex.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:386945
URL: http://admindepartment.ir/arinze/arinzex.exe
URL Status:Offline
Host: admindepartment.ir
Date added:2020-06-11 15:42:12 UTC
Last online:2020-08-25 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-06-11 15:44:05 UTC to mehmet{at}vitaminbilisim[dot]com)
Takedown time:2 months, 15 days, 1 hours, 7 minutes Bad (down since 2020-08-25 16:51:54 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-25n/aexe aec8fdc885479ec823e814d26a70179e19593b013c41b421b89c40fbd2f48faan/a 
2020-07-22n/aexe 6e06a523abadadf80dadbabf1543c4610224a80e0ee7e37bff1a2e2895300442n/a 
2020-07-19n/aexe 7329db9d896ef50f5e584d9487abd56473bdc5769f1a1768a64ef339619ea9e3n/a 
2020-07-10n/aexe 63d350fe26f6794e59fbec3672582224b61f1f4c73dcb65b9ce9b683625c5b49n/a 
2020-07-05n/aexe 719c26761fb85e6d89c6e6ac213afd5845c232c8024c12f003b764e45d32452an/a 
2020-06-24n/aexe 9d7b60918b46f41b880d6d2adb266bec969f4a38f3c293758e2fb8aa32d78907n/aAgentTesla
2020-06-22n/aexe f223424159fed8e0274d278568320d8b396aa5e3b218964e81cee2e91e2dc4d1n/a AgentTesla
2020-06-16n/aexe 90a88126d463ddacf834849139c7c1e4254661ff3302d68157f08cff319c216bn/aAgentTesla
2020-06-15n/aexe 3345b110a3dbfba2ecc7fd2c026415b868ab5ec791551ab2087cf0dc203551b6n/a AgentTesla
2020-06-12n/aexe fc479e25d36a5a94c3656beb9128af5e7ddd2338e804e87d1b3ad5f748fbd953n/aAgentTesla
2020-06-11n/aexe 00983ceacb517a28cb191d71c4907a201bd5d24d872276bea84b51805676b824Virustotal results 34.25% AgentTesla