URLhaus Database

You are currently viewing the URLhaus database entry for http://abass.ir/cairox/cairox.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:436422
URL: http://abass.ir/cairox/cairox.exe
URL Status:Offline
Host: abass.ir
Date added:2020-08-19 09:50:12 UTC
Last online:2020-10-23 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: ps66uk
Abuse complaint sent (?): Yes (2020-08-19 09:52:02 UTC to solisomama[dot]john{at}gmail[dot]com)
Takedown time:2 months, 5 days, 3 hours, 5 minutes Bad (down since 2020-10-23 12:57:37 UTC)
Tags:AgentTesla link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-07n/aexe a2c5f74931c1d6871db672270876c1cc80bc90d4b4bca32355b95e762d30e246n/aAgentTesla
2020-09-07n/aexe ecd0c9515106232ce9cb2e64bd93d688a4e6211dd0a42582f39435c3652ccf86n/aAgentTesla
2020-08-30n/aexe f973277a035ffef0b6da3768b836cb041895b7db7d9af0e89dbd2af3a55b3dfen/aAgentTesla
2020-08-28n/aexe 313c9b480b0f3fa74f41766b326428ea31b40de7800f5597d3a7614fd02b6691n/a AgentTesla
2020-08-27n/aexe 09572618588c1d2cdb0b6bdf1d0675bd953a531f43f045ba74a96cbf922cc70en/a AgentTesla
2020-08-24n/aexe 01e945bb7c4e8f19354f1980677f0c440678c54a4b5864803f2f7f899242c4e1n/a AgentTesla
2020-08-19n/aexe 2d46563299d082503b9f75878a83c210a31e1e4bcbc2923c2b63a5292bf800e6n/a AgentTesla
2020-08-19n/aexe 954c9a92e5e95783711ac9da044757457e9428c0e9f3cb58f03f3acbc2c59c22n/aAgentTesla
2020-08-19n/aexe 3a8be88ca9b919ae064904c09b8b16e07cc4e144b6ea8f39cd645ce58fb1ac57n/a AgentTesla