URLhaus Database

You are currently viewing the URLhaus database entry for http://gooddns.ir/trulex/trulex.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:460186
URL: http://gooddns.ir/trulex/trulex.exe
URL Status:Offline
Host: gooddns.ir
Date added:2020-09-11 00:27:38 UTC
Last online:2020-11-11 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-09-11 00:28:06 UTC to solisomama[dot]john{at}gmail[dot]com)
Takedown time:2 months, 1 days, 0 hours, 5 minutes Bad (down since 2020-11-11 00:33:19 UTC)
Tags:exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-01n/aexe e5d8344ae7d9f2641a4e564d0e6e1a6494e216e6a5be0355eb45190e25d11f8fn/aFormbook
2020-09-24n/aexe 54c0138d6a0dbd5967d7cf51eb753b29aa1fd72a85152285bd22347fa6654022n/aFormbook
2020-09-23n/aexe 8c6589747dd18d5160664041b3f47111ddf5fb35a3223ec798d501b1904c9fadn/a 
2020-09-20n/aexe 17de42648d49e21ed411c460fa0c805443e1898e21114beb8ea7301da3ee6b31n/aFormbook
2020-09-18n/aexe 15af9bb36b7a51efea7ab70d98a29ef7059f4f5b7178fef0aaff0671bf6c9386n/aFormbook
2020-09-16n/aexe 34eeebc4197df0980b621253c336662f3868ccc65a5f99a832d47751d4d5384en/aFormbook
2020-09-14n/aexe ca90c99e774262109f3383c71fa9255eb169b25ef891b7b064199bc393b2ab4dn/a 
2020-09-11n/aexe 61755c45dbcb0e63d5b14759567d9761bd9299f9cee1830b3bfe163c44738b1aVirustotal results 42.03%