URLhaus Database

You are currently viewing the URLhaus database entry for http://admindepartment.ir/wealthx/ecomx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:393746
URL: http://admindepartment.ir/wealthx/ecomx.exe
URL Status:Offline
Host: admindepartment.ir
Date added:2020-06-16 15:53:13 UTC
Last online:2020-11-11 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-06-16 15:54:07 UTC to mehmet{at}vitaminbilisim[dot]com)
Takedown time:4 months, 27 days, 8 hours, 43 minutes Bad (down since 2020-11-11 00:37:41 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-27n/aexe 3375ebdd6b86a65de02eff797ad80b7c11a9c7141a169fdb97eb8bd593aa12c6n/a 
2020-07-07n/aexe cd03561f0a0473dd4c477e139012d4b52f3ef7cd0f02c1ad506cd69f13f844bfn/a 
2020-07-04n/aexe d0aa937abece7fa493148a87ab28dcd092d5da21f81efa6eeb2db7c496a34904n/a 
2020-06-24n/aexe 774b96525607e99c817973a4fc9279c70ead81b7c3347b8ae5e0aa202c8606fbn/a 
2020-06-23n/aexe 87a0795dc92456c39733e634ca8f189db0e0d8e90bcf755fc7950f121b25c426n/a AgentTesla
2020-06-22n/aexe a8493f7f577842b2f66475a3188e6c15610feed12ad50ec086aacdd99cb5ee7cn/a 
2020-06-16n/aexe e3760b093e7f9a12e97bc7a0719eaf9e6c4e86fe5bebf3556f9a0c117ea283b8n/a AgentTesla
2020-06-16n/aexe 63fc3b0b471168010c1f4552579de07cbdcaf074aced788680a423404996288cVirustotal results 34.72%AgentTesla