URLhaus Database

You are currently viewing the URLhaus database entry for http://85.202.169.21/petitzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2248855
URL: http://85.202.169.21/petitzx.exe
URL Status:Offline
Host: 85.202.169.21
Date added:2022-06-24 13:02:04 UTC
Last online:2022-07-16 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-06-24 13:03:05 UTC to abuse{at}serverion[dot]com)
Takedown time:22 days, 4 hours, 11 minutes Bad (down since 2022-07-16 17:15:03 UTC)
Tags:32 exe Formbook link GuLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-07-13n/aexe 12821451d62eb9126a3394e1abcaa6b68529976d1a3272793c6af2ed86aea8f3n/aGuLoader
2022-06-28n/aexe cb9934d2f592f67086f8c33eaf75eab1d048b9985b6acf297aca4c98d07ddda1n/a Formbook
2022-06-27n/aexe 6b25f21416124c71e80f43707efa109c389b16c3c2ac651d12a7fe14a996abc3n/a 
2022-06-24n/aexe 8370746ea957582a6e53d4ffb81c864b484d73cbea2904b040375ee851bcb06dVirustotal results 41.79%Formbook