URLhaus Database

You are currently viewing the URLhaus database entry for http://pushing.pk/myzip.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:408718
URL: http://pushing.pk/myzip.exe
URL Status:Offline
Host: pushing.pk
Date added:2020-07-07 18:24:38 UTC
Last online:2020-10-08 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-07-07 18:26:02 UTC to abuse{at}selectel[dot]ru)
Takedown time:3 months, 2 days, 16 hours, 43 minutes Bad (down since 2020-10-08 11:09:37 UTC)
Tags:AgentTesla link avaddon exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-06n/aexe 551022935cb64a9df1e36625a3be468c99a25086b505a4dba1c533f3f749c7a4Virustotal results 18.57%RedLineStealer
2020-10-04n/aexe fe40a261819b8c1f1308aaded3d797fd2ade74c2bb23f51deedc4b5b0c0f2d6fn/aRedLineStealer
2020-10-02n/aexe 082f1317f03b76584194dc5b800ed466cc1fbef34ef63a6019c2dc1de47212edn/aRedLineStealer
2020-09-30n/aexe b3fca64403f07425370908447ab64f319dc0123dfc76e6069193af03878e1651n/a RedLineStealer
2020-09-29n/aexe 02ac362c98153af0e02dc068c4433c4a776776ddaf9a61507a1861655b466052n/a 
2020-09-28n/aexe 92505b3a3135413987ec32776f6e8fdbb95489bc81b8a0cec50f4569a1b9e055n/a 
2020-09-27n/aexe d0d65472e2add0a503c45b2d03a644671ad5400e2dd59e0f6193217e028b2570n/a RedLineStealer
2020-09-25n/aexe 4bcd16af2791ebba58ab162c928e238197c14735650f73e98fc471ad677ab13an/aRedLineStealer
2020-09-25n/aexe b435ca26bf3bfd2577b333139205f38164bd079081269d1dbbd9707a50326309n/a
2020-09-25n/aexe 1888fccd20932633c7a2a0706b4efd012722e10e7a4898a4f7b84e4b7c3e04d5n/a 
2020-09-25n/aexe 004ecb4c2e9b088e9f09f9f3db04598f10092ecdb7bfacc76bc36442e70a3f38n/a
2020-09-25n/aexe f3bfce4f6dfd966e35ca0ba2d285a13057a738e71fd692f8730eec2c6cf3f94en/a
2020-09-24n/aexe 0403b60e129fad4636706596c62683fea3aa290409b507fcea13035160d70af8n/a 
2020-09-24n/aexe 6aa9cbe3ea49cf8d0ef07f2971f94520048cb86587c43662e83a02cbb6229e81n/a
2020-09-23n/aexe 8611b66792009b09d0b2459319d53f4bc276400c55db9ebeb88527526d727156n/aRedLineStealer
2020-09-09n/aexe 3481235147e1800772079eba0f3df848735378b9711d3a11b90141a01de3898bn/aRedLineStealer
2020-09-08n/aexe ca1104a79514d23f1d60fc6e92e626a6a29c3b217bdf30324237c7d12c5dfb10n/aRedLineStealer
2020-09-03n/aexe f25bac7d622cd257c9668067e7499c0587e14f5c9719177df836c0778a420ee2n/aRansomware.Avaddon
2020-08-27n/aexe 40f2f1b52877c4859614a065d6d538c9c07e6dfe7b763d76c2919daeda7cbbebn/aRansomware.Avaddon
2020-08-26n/aexe cc7852dc77152c57aa51e7b7dc34e09e086bba8845334d28d652b07adbc651bbn/aRansomware.Avaddon
2020-08-02n/aexe 4a29b0f61b09b0e5f6736021f3fddde78737f8bd24afbb61fbb67999a09ebc7fn/aRansomware.Avaddon
2020-07-21n/aexe c7c9f8f68348fbd26aae20c9ccb1aefd1cfce63897efa4c64abe7ac480253259n/aRansomware.Avaddon
2020-07-20n/aexe 7b7c16367746efe7583ae46235b2f062ce44602dda990c9a11a730d619b8d365n/aRansomware.Avaddon
2020-07-17n/aexe 8fe2bd58f017604f70b5bb8b9a34485338c4c9bdd0d2ea0f1b78d8dddbcc4968n/a 
2020-07-16n/aexe 084ec0f81653cf53dccab91db3f9593176e6ef076786372ec101bdd8fe75cea9Virustotal results 18.06%AgentTesla
2020-07-15n/aexe 97f507127a0a652f0d11399a2d05302512df3b78b2db44d8ff5da4453076c483n/a RedLineStealer
2020-07-14n/aexe 63482059c9435e0cc5acf76db1855a8bec6bafc36062d5e0baa3f814c7643a6cn/aAgentTesla
2020-07-08n/aexe b74e722c4a7b85d49e9c25991528d742161a1ae76c860e001868b1918dc66222n/a 
2020-07-08n/aexe 692dc7ac48dfa381cd7f860236876e3621af2e1dc984b8f14cad498e412e88d8Virustotal results 14.29%RedLineStealer
2020-07-07n/aexe 6ad2831339a2a6fc8d140c8718cf38fabef9915409bd32cd86221b515b4be629n/a