URLhaus Database

You are currently viewing the URLhaus database entry for http://85.202.169.21/blessedzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2252179
URL: http://85.202.169.21/blessedzx.exe
URL Status:Offline
Host: 85.202.169.21
Date added:2022-06-28 19:06:04 UTC
Last online:2022-07-16 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-06-28 19:07:05 UTC to abuse{at}serverion[dot]com)
Takedown time:17 days, 22 hours, 9 minutes Bad (down since 2022-07-16 17:16:23 UTC)
Tags:32 exe Formbook link NanoCore link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-07-08n/aexe c8fb2b38dee96b9bf7b199c9ac198238826b00b48d00048e64f54656a814535cn/aNanoCore
2022-07-07n/aexe 49cd361598bcbe364192e8cf8a6c3ae74bcf86a08c8dc58e7514625fdba2beacn/aNanoCore
2022-07-07n/aexe 00134e71df62b202f08b6faacf6b37e07bc8877596efbca9406fd2bd8f5b99c5n/a NanoCore
2022-07-05n/aexe 1b070743f2def599e7be48213af18b2981ab6b0d26c74ddf96cd6696535008a1n/a 
2022-07-04n/aexe 96c469742ef0e74fd57d76c78c4f14ee6ae47e3af41baec4cdfb46f6d637160dn/a 
2022-06-30n/aexe 0464dd900688ae0a6110dc7e64fa0002de2f54514a450fe262d264706084eb7dn/a 
2022-06-30n/aexe 6325643c3ab38280584592f73029b8ed0bfc1c569fbf26f74033c634d7a2d7e9n/aNanoCore
2022-06-30n/aexe 9a7709d966ff3807ee84a5b751f5e9b443307f9c9e37939cd29771279adb98f4n/aNanoCore
2022-06-30n/aexe abba5d05324ebbb882f9bd6edc4b46962ef0fd95fe442cdbe4c3762b02f720b5n/aNanoCore
2022-06-29n/aexe 29e46788118cf17b864f25563d149a9f56e13183d69a0ea9f8a40b93a98d7792n/aNanoCore
2022-06-29n/aexe 13f409b60b9a72911c24840af2823a357783ac42298b323c098263d99e03efaan/a NanoCore
2022-06-29n/aexe 3ed29b38e6c28ae5715eb7baf2cb23553aa0eff9ac62b6ce3de802e5cdddb116n/a 
2022-06-28n/aexe 44ba464299c1448fd6ed5e515f4edf818610086438fbdc498f899c79e8b44568Virustotal results 37.31%Formbook