URLhaus Database

You are currently viewing the URLhaus database entry for http://admaris.ir/tonex/tonex.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:390060
URL: http://admaris.ir/tonex/tonex.exe
URL Status:Offline
Host: admaris.ir
Date added:2020-06-15 11:19:36 UTC
Last online:2020-07-14 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-06-15 11:20:03 UTC to mehmet{at}vitaminbilisim[dot]com)
Takedown time:28 days, 19 hours, 34 minutes Bad (down since 2020-07-14 06:54:34 UTC)
Tags:exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-05n/aexe 3c01144859426d0453301354cc3446b9da3fd8d11d46eee9b66327c5e4e3ebc8n/a 
2020-07-03n/aexe d77852006b27141d5d508fa7ff80c2ea78520bbdcf1829c1df5d12947c498b90n/a 
2020-06-28n/aexe 0a16bc562fe6301d46211c399bf31b06dc7986a0d186037466c5160258a02359n/a 
2020-06-17n/aexe 2a631417b4ea91f5b4e38c91638ad55b51352a0585d90de21488238957c4537cn/a Loki
2020-06-15n/aexe 6b85aba8655a2f157a474bf452f707a27010fb66651c8ec1652d94587c24f86an/aLoki
2020-06-15n/aexe 296e6609c5ff7200a36b12fcad2f74a03e82b2a90055a9bcb4f2f9eefab5878aVirustotal results 37.50%Loki