URLhaus Database

You are currently viewing the URLhaus database entry for https://irregnancised.com/ftiloe/KHFOPL.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:422724
URL: https://irregnancised.com/ftiloe/KHFOPL.exe
URL Status:Offline
Host: irregnancised.com
Date added:2020-07-31 09:24:35 UTC
Last online:2020-08-02 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-07-31 09:26:02 UTC to abuse{at}quadranet[dot]com)
Takedown time:2 days, 1 hours, 51 minutes Poor (down since 2020-08-02 11:17:13 UTC)
Tags:AgentTesla link exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-01n/aexe 7afb56dd48565c3c9804f683c80ef47e5333f847f2d3211ec11ed13ad36061e1Virustotal results 0.00% 
2020-08-01n/aexe 601cdbddfe6ac894daff506167c164c65446f893d1d5e4b95e92d960ff5f52b0Virustotal results 0.00% 
2020-07-31n/aexe 5562f4b4cad8370a3321331a7192bc2743eeaa5529563e70c9b1f6f31c389197n/a AgentTesla
2020-07-31n/aexe 9e66dfb8bc283a6f942a684db958e6e33f49e041401da7523b8acfcb2a01ef9an/a 
2020-07-31n/aexe 8000c419cdf35f38a730c8e4946e842d327fc2e9102ef2d0f62cd7a154dd5961n/a AgentTesla
2020-07-31n/aexe 0821c911e99efb3bcbdd8e93d83a79a004e122a0b5c9247a99d68023edba088cn/a Loki
2020-07-31n/aexe b6c1578da26c1c35f1806ae0c80d2cd81817a2e9de0a69e72f0b9dcd3013cc3fn/aLoki
2020-07-31n/aexe 82413d12d17b0e3b236f8c9e3964eff552b6a95a7732efbc28607b4a58f58d91n/a Loki
2020-07-31n/aexe b64ddd178d652c5432004449edc53fea2abdba8633259b4d8b329e1c8484e98an/aLoki
2020-07-31n/aexe 15e84355978fd585af794a5aa1b61144a9197d1410219a4e129aca0ce953904dn/aLoki
2020-07-31n/aexe a550b01785417d0c802740cb128aa26d4415414458b87877b634bed5c2694ad5n/aLoki