URLhaus Database

You are currently viewing the URLhaus database entry for http://paxz.tk/obizx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1907407
URL: http://paxz.tk/obizx.exe
URL Status:Offline
Host: paxz.tk
Date added:2021-12-21 14:27:49 UTC
Last online:2022-01-12 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: James_inthe_box
Abuse complaint sent (?): Yes (2022-01-07 21:34:31 UTC to abuse{at}serverion[dot]com)
Takedown time:1 month, 25 days, 10 hours, 30 minutes Bad (down since 2022-02-15 00:59:51 UTC)
Tags:ArkeiStealer link Formbook link OskiStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-14n/aexe 8c2c738ee2230ec142259f31fc60cd23ce3bac65dec24427437ec79250fa3653n/aFormbook
2022-02-07n/aexe d5f77ba2b2ad58cfad5ae3111994ad0f889967e6d4f67ecb9cedf1b8f10a6149n/aFormbook
2022-02-02n/aexe 114505961db31e8df89e72793bdab23348cfde742a30cfd7171047a61d23af84n/aFormbook
2022-01-31n/aexe 127d5e23957003ea84baea35da99f1095e51d4b3f48255251a062237f6af005fn/a 
2022-01-18n/aexe 22633ca2e23a6d2353a4a2a4f87b02548fc9c9e92b4e482df9bae8e93c17b793n/aFormbook
2021-12-23n/aexe 05aa9412aeccb4fb7bb68162a94224fa08a292a74b312864fd4bca4083ba7d9dn/a ArkeiStealer
2021-12-22n/aexe 7d8720a816740e98db989e14ce75f99de9bbd25924fbbbaf7a8d0c783c612579n/aOskiStealer
2021-12-22n/aexe 31ca3fdcebbf4f26080dde1ad37e8b40f391709b27fce27cf3aa7bca725aa193n/a ArkeiStealer
2021-12-22n/aexe 50be21ecf485dbb500b311c0bfcb3c2f3f1d1ab22957d84a04c271d016d1ea20n/a ArkeiStealer
2021-12-21n/aexe fc55c796977aaab2254fd98cd04595c9eab86f459f3288f5f33d8fc9f050fdc4n/aOskiStealer
2021-12-21n/aexe 2483e3d38f1856bf14e1bd86692e4ac5b3f330a52166d7708fba883a6809595bVirustotal results 22.39%OskiStealer