URLhaus Database

You are currently viewing the URLhaus database entry for http://gooddns.ir/max/maxfrnd.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:599528
URL: http://gooddns.ir/max/maxfrnd.exe
URL Status:Offline
Host: gooddns.ir
Date added:2020-09-22 19:00:37 UTC
Last online:2020-11-11 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-09-22 19:02:06 UTC to solisomama[dot]john{at}gmail[dot]com)
Takedown time:1 month, 19 days, 5 hours, 37 minutes Bad (down since 2020-11-11 00:39:28 UTC)
Tags:AgentTesla link exe Loki link MassLogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-11-09n/aexe bcfa4551e66deea775dee52f97f9d5806d16441c0d82f045a16e49340313ee54n/aMassLogger
2020-10-26n/aexe 40e91b54dfb08b396759074f6018c28433f771a9c6c66ff5b1789d786c591c87n/aLoki
2020-10-15n/aexe f6f18336f32f52ccbde6b1e31304eb4952beb16fcb6357e8442f669dad47b7a2n/aLoki
2020-10-14n/aexe ac04290c3e7987172725a684e7dfe521011ed939565b40fab96c2732420c01a6n/aLoki
2020-10-13n/aexe 3690ee8b15550b1ac997b497e19b0b556b78cd80747d458c09ed8185a55410f3n/aLoki
2020-10-05n/aexe b3f2d07e97cfe28deee3a65b8541c48f96f022b52db515b06c635f3b9fcc35efn/aMassLogger
2020-10-05n/aexe 553ad8c805d4151e154177bb4fbb1678711306d8eefba081ec36bf0518d4e88fn/aMassLogger
2020-09-22n/aexe 26e69b176a99a4c9490c9dae46d755e7dccd44e7820a6465dd379d7687884cfdVirustotal results 41.79% AgentTesla