URLhaus Database

You are currently viewing the URLhaus database entry for http://mashhadani.com/z/a.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:5091
URL: http://mashhadani.com/z/a.exe
URL Status:Offline
Host: mashhadani.com
Date added:2018-04-13 12:16:40 UTC
Last online:2018-09-08 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: oppimaniac
Abuse complaint sent (?): Yes (2018-06-11 10:45:48 UTC to abuse{at}publicdomainregistry[dot]com)
Tags:exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-04-24n/aexe 134d90fb2570160e1a05400a70932e01e935a6fa7919a23566f08ee20a343f98Virustotal results 26.87% RemcosRAT
2018-04-23n/aexe 18d690404357b1954b8445d1c7a9422763d46123e08360b62980696286cc88f8n/a 
2018-04-22n/aexe 38368e9d61f2ac8ad830b072ff65e902dfa835082d0ae56ae4af74a5170f9f0an/a 
2018-04-19n/aexe 1f2b3d6e68b7757e37548b8783f69806836415dd688625245d103358a4e7690en/a RemcosRAT
2018-04-18n/aexe 80bc732532d75d041f3ace0dd1493dac2da05ac519cfd8a93782b81e574527e8Virustotal results 16.42% RemcosRAT
2018-04-17n/aexe bdbee0aa847efa4f1695e1caf8dd553f99080575c7f4b72c0fe009e4d14f5187n/a 
2018-04-17n/aunknown e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855Virustotal results 0.00% 
2018-04-16n/aexe 983378733691ff661167a1125f753159e255b8c1e8f46b2afb71201e85a9b23fn/a 
2018-04-14n/aexe eb0d49d6d314ca2fba31ed4fb38fb3a43a7664fcee06b8b0179b83e08aa5e473n/a RemcosRAT
2018-04-14n/aexe b67f022f725cf008e60f2edc0688c8d0f5a8c79c1b0c33c474d578b0ab4f7925n/a 
2018-04-13n/aexe c89e27634a8d8b44ff0d8ce087e2dbfbbbd1bbd157fdaae14f4faaabded6bf8dVirustotal results 15.15% RemcosRAT