URLhaus Database

You are currently viewing the URLhaus database entry for http://gooddns.ir/nwamax/ldx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:460170
URL: http://gooddns.ir/nwamax/ldx.exe
URL Status:Offline
Host: gooddns.ir
Date added:2020-09-11 00:22:40 UTC
Last online:2020-11-11 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-09-11 00:24:06 UTC to solisomama[dot]john{at}gmail[dot]com)
Takedown time:2 months, 0 days, 23 hours, 55 minutes Bad (down since 2020-11-11 00:19:54 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-22n/aexe f0e6e6fef9203d99ebd684d0cef134b076d0cee40a64c04ede7c7ef062e8db62n/a AgentTesla
2020-09-22n/aexe e169043db0da14b9d2b093e3bb7e3b223a5ef91a3adb2bb70b7c9fe10d6d34aen/a AgentTesla
2020-09-21n/aexe 0d38cce24d349ab7c0ed29d24fa3686a525d5c8904a12e744ff872069523a4fan/a AgentTesla
2020-09-18n/aexe f7a21b812eaebf24b601f897d3287979247b6025b1e20841ad8b34ec5d1c6575n/aAgentTesla
2020-09-16n/aexe 5c53dc947d2083d3339c1522bc44363cb007e0a6fa314198958ad92d870c4425n/aAgentTesla
2020-09-16n/aexe 24a011cf95c7b98ace8435f99dd63c939d34cacb6f386dc2ecb8611c13b66fc0n/a AgentTesla
2020-09-11n/aexe bf6685f531efdf06db86ed0e735fcbe612858213677111ad900a02164cd77efdn/aAgentTesla
2020-09-11n/aexe f2973b8c16753b971c462fcd46bd32a5a5d889ad145ec1e6e8c6efc94c7de313Virustotal results 42.03% AgentTesla