URLhaus Database

You are currently viewing the URLhaus database entry for http://admaris.ir/atlasx/princex.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:410522
URL: http://admaris.ir/atlasx/princex.exe
URL Status:Offline
Host: admaris.ir
Date added:2020-07-09 14:22:15 UTC
Last online:2020-11-11 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: James_inthe_box
Abuse complaint sent (?): Yes (2020-07-09 14:24:02 UTC to solisomama[dot]john{at}gmail[dot]com)
Takedown time:4 months, 4 days, 10 hours, 12 minutes Bad (down since 2020-11-11 00:36:58 UTC)
Tags:AgentTesla link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-19n/aexe 88aed98893b5c7e068c6ecaff530c83d8033e2bc7516931794e17b4a7b194442n/a 
2020-07-15n/aexe 89b909db092103e2ee9a9fd99bb8be856c6ba10429411eb6cfd56f796752dee0n/a AgentTesla
2020-07-14n/aexe 2847c74cc23c17f1806f036db79f0e1b1cf111366886b5f8114b16a344d85119n/a AgentTesla
2020-07-13n/aexe 0dde348228b5ad99d94e434be378b31e114ec0dbb9a008db1218d3a349ceea8bn/aAgentTesla
2020-07-09n/aexe 3a052762219035c320097a6a2c59f3023b69ed8022d1b4cf100aafe3446c9698n/aAgentTesla
2020-07-09n/aexe 934982623de62355613d2c7e8f8d1edee0a5db84c99636fb9ee543e7cfc6a079Virustotal results 46.58%AgentTesla