URLhaus Database

You are currently viewing the URLhaus database entry for http://37.0.11.227/files/brownzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2214416
URL: http://37.0.11.227/files/brownzx.exe
URL Status:Offline
Host: 37.0.11.227
Date added:2022-05-27 16:32:04 UTC
Last online:2022-06-06 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-05-27 16:33:06 UTC to abuse{at}serverion[dot]com)
Takedown time:9 days, 19 hours, 47 minutes Bad (down since 2022-06-06 12:20:45 UTC)
Tags:32 AgentTesla link exe SnakeKeylogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-01n/aexe 87f1db5a40fe083e9ff7ee637095f1ee85cb1eeb94805a6482969f167b7bb8cdn/a SnakeKeylogger
2022-06-01n/aexe d21743370f3143c90aba3ff67a9e2e381d836423ab72e1c7f4e565d95689e017Virustotal results 30.88% SnakeKeylogger
2022-05-31n/aexe 90280c7a3af8de5451e55f58d30d64572df9c0431471bb084292d202263126f8n/aSnakeKeylogger
2022-05-31n/aexe 061f4f8dc9e0e9b7fb85efb74cce76cb7a358ac107e6f3e49f997b6b41622b84n/a SnakeKeylogger
2022-05-30n/aexe 3d15d2f54236b492acbdeef2e16c6b045dc877d88c70597c62e46b6dc9f9d3ffn/aAgentTesla
2022-05-29n/aexe 263cfce25c709a67b094d25d6c04fa29d37eae14f808ded5b252dc656b28866dn/aAgentTesla
2022-05-28n/aexe 44f95f7722ee82b8390796228e41e45aa53052ad66b4d74c12d5010faf54429an/aAgentTesla
2022-05-28n/aexe 1ddff7b1143ac407181bb571180118602fd5c7b8756ce1828f37b68fc24ae077n/aAgentTesla
2022-05-27n/aexe 3765e92234de653b426472c63f4209801cfce1c231a3c88f5ca9d44d6b317251Virustotal results 38.24%