URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/nzezx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2259316
URL: http://208.67.105.179/nzezx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2022-07-20 13:50:05 UTC
Last online:2023-01-19 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-07-20 13:51:05 UTC to info{at}serverion[dot]com)
Takedown time:6 months, 3 days, 3 hours, 15 minutes Bad (down since 2023-01-19 17:06:56 UTC)
Tags:32 exe Loki link NanoCore link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-09-06n/aexe 968af11867e0ca9cb7ca9898b77d6a78a05feb457224f92634df0b3ecf4e0be2n/aLoki
2022-09-05n/aexe 0725ef86714cd23fc66a5e8a6e2283f0035c7304354476a951e28c0de63aeab6n/aLoki
2022-09-01n/aexe a0af04aeb4d0bd20a2ac8089b0f88b1935d8334400d7190b2751be7d53e16716Virustotal results 27.14%Loki
2022-09-01n/aexe 8dd48efe8e0436ade87dc00c9e525fce417024ac04e9ac060ecb384ec67f0951Virustotal results 32.86%Loki
2022-08-31n/aexe 3ac36b3612907df3fd1724900c917c215ef9bf6c5530c81d3b40a1faf7447b90n/aNanoCore
2022-08-30n/aexe 1d2147500bdb626e9f78761c9d25a8d597f3d966e5437efb461f03b3ec8be217n/aNanoCore
2022-08-30n/aexe 52cd482b7219eb54f7e9e4672d58d8bd85fbbb3468d2da6fac5b719b3a934f65Virustotal results 20.00%NanoCore
2022-08-29n/aexe b95f5f68948d08e06292fbda648e99b3d7d237e19cb4da03fc729fddd681d195n/aNanoCore
2022-08-29n/aexe 747e7a2c12b9ecff95e0828ab061ac6d75a722005bbce2555b6c5353eaf9e23fVirustotal results 19.72%NanoCore
2022-08-25n/aexe 3a8064e4524a52d53e9b2111c5368c82182dc885043b43373f56f7532b268e29n/aNanoCore
2022-08-24n/aexe ed627832d80a82faf49c5a61bf7fef509f4860889ece7d18388ecbe2110f7dc6n/aNanoCore
2022-08-24n/aexe a34669a4f919bfb5c570b7d5ad5eea4f5fdb276268afbdb6b540907f1ddefa83n/aNanoCore
2022-08-23n/aexe 701768dfd24a5df7d5ad448c9bcd933fbef87fca11c91c457cfa44d95e2fb6d1n/aNanoCore
2022-08-23n/aexe f744326dd8c1d2d254759fed22d0f8d1ce7df89ec0c699a896450773f110355an/aNanoCore
2022-08-19n/aexe 0ce9fcd692bc34e751910d4698453b577677fa2883f978af28e6753a963e30dan/aNanoCore
2022-08-19n/aexe c27008bd825faf145c4d214450c1044c3927d01a2d7da850da862c51018d0ccdn/aNanoCore
2022-08-17n/aexe 25dc2daecc1f213eb7e68141aca9e9917e2ba93fc30bafd050f84d7e1f0bd3d2n/aNanoCore
2022-08-16n/aexe b975300b29a918ba9b96365e073aecfd980ee79e3b83095373b88867ad7b29f9n/aLoki
2022-08-16n/aexe 98e7f088ba419732a641ff92685cda6f57ce183883be240d30a51d2e9eed0084n/a 
2022-08-15n/aexe 99f63fbd83aeadba7be7424ed0deec82ef18ae2d5c8d543d4ccb2de113f4cffbn/aLoki
2022-08-15n/aexe 52f0382ddec3efb2c092b4199fb537eebd8cbd1ed1fa0ed321fea2a723dffc13n/aLoki
2022-08-15n/aexe 8b345c4fef0497cdad8342ec52e8687fc0b572021de79bde4c8dd72bbaf4bbb2n/aLoki
2022-08-14n/aexe ee98cbdd948d8fb8b7ab1803d2739e438b2fd193a37925db8c2e208b92713c78n/aLoki
2022-08-12n/aexe 4ce80bb4169f81656f9f5a2833aad35378d7e26fe9fcce2da3e5628a8d4693e0n/aLoki
2022-08-12n/aexe 4cc1d7c1de7318ad6e31b2d8653933c450e6ce76c4d750df7d3ff6238d70c404n/aLoki
2022-07-20n/aexe 0113fa893a036c81b7331934cef9314bf925a28daf77365316ad4aaaa7ef9b7aVirustotal results 61.29%