URLhaus Database

You are currently viewing the URLhaus database entry for http://admaris.ir/bobbyx/divinex.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:392838
URL: http://admaris.ir/bobbyx/divinex.exe
URL Status:Offline
Host: admaris.ir
Date added:2020-06-16 06:10:10 UTC
Last online:2020-11-11 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: cocaman
Abuse complaint sent (?): Yes (2020-06-16 06:12:02 UTC to mehmet{at}vitaminbilisim[dot]com)
Takedown time:4 months, 27 days, 18 hours, 24 minutes Bad (down since 2020-11-11 00:36:09 UTC)
Tags:AgentTesla link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-05n/aexe 049fb580bc388432a3d7236b50cb3b5cd7493bb6e8b51c573e6d81730773cb68n/a 
2020-07-25n/aexe 1d645582ce99901e0c7eb06220ce8a994934f36c5445386e51036dce33922b73n/a 
2020-07-19n/aexe 200e227ab3b36c308241ddb5c3ef7a1c9e9df2a5b792d9bb41fd402d89f26c33n/a 
2020-07-05n/aexe 2aeeba9c6e6cdd580ee3e225c6f6c1346aee527e8ffaa493d9fba540c96397een/a 
2020-06-30n/aexe 51d7d52de0b0a0193734fb70c48e22e968365cc583ddd8aa25bdf45efc63d353n/a 
2020-06-16n/aexe 146a89d90f2bbd4b7a788843492927cd3ffe7c05ca69a581c1c3ee5a749797fcn/a 
2020-06-16n/aexe 72601c184a73a3def992b0bf596508387d7aa5dce9188be7840c1c25a9cbe7acVirustotal results 38.36%AgentTesla
2020-06-16n/aexe 9085ffe21d4f55f9aaa5c9e63618b0a599ed6f7c6ad6f054fbd06ecddd5321e8n/aAgentTesla