URLhaus Database

You are currently viewing the URLhaus database entry for http://85.202.169.21/bluezx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2251961
URL: http://85.202.169.21/bluezx.exe
URL Status:Offline
Host: 85.202.169.21
Date added:2022-06-28 08:33:04 UTC
Last online:2022-07-16 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-06-28 08:34:05 UTC to abuse{at}serverion[dot]com)
Takedown time:18 days, 8 hours, 41 minutes Bad (down since 2022-07-16 17:15:12 UTC)
Tags:32 exe Formbook link SnakeKeylogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-07-07n/aexe d90649023e828580e01a50d34142fbeb7495d5c7f9ccbe813183055c5c15885bn/aSnakeKeylogger
2022-07-05n/aexe 2ec4c1f1ffef7845a945dc1ad00d3e3f866a719c2d876847f1d2956fdf0197b7n/a Formbook
2022-06-30n/aexe 714a619165308ef492029ca21f0c072a5d643427e08af2335a9688fb5070f0cbn/aFormbook
2022-06-28n/aexe ccc73750875569ffe5f35b1d285255e3e3fe171a04192230486d75926ad07257n/a 
2022-06-28n/aexe a2e38d4884cd9695e60fe38a8ebf15d7ed77bdf121212282aba5389b550c4d0eVirustotal results 35.82%Formbook