URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/governorzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2259317
URL: http://208.67.105.179/governorzx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2022-07-20 13:51:04 UTC
Last online:2023-05-17 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-07-20 13:52:05 UTC to info{at}serverion[dot]com)
Takedown time:10 months, 0 days, 21 hours, 20 minutes Bad (down since 2023-05-17 11:12:29 UTC)
Tags:32 AgentTesla link exe Formbook link Loki link SnakeKeylogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-17n/aexe 4a71db3ff6a24f0c64d2df54b0dfddd9a2b630b2ecfd03b4abf8389d825095cen/a 
2023-04-14n/aexe 2713d5f063d131de0d8ab8c4768401364b4f512c7b79cf6ab14f8d596a725af2n/aAgentTesla
2023-04-11n/aexe efef5957e7daeafd76164150df18bba059df05259ffcf77659133e12925540fdn/a 
2023-04-10n/aexe 8a7ad0ac9a02dffbfd56debb206f3ab221974ef81540861409ffc412873d3da6n/aAgentTesla
2023-04-07n/aexe 2b6cc55a9969aff7f49cefaf7dcc980978720a9008e378f4f99d97a8d760d285n/a 
2023-04-06n/aexe d26449a86fb463c573cd383b333c1d807165762718c9d4fd78c1cf15c70e1f98n/aAgentTesla
2023-04-05n/aexe 0d2d3cc50572a90b68558d070375be0474a2294f5cc1d4ac0249b19f21d12d8bn/aAgentTesla
2023-04-04n/aexe 117d6cc2cc059670b2917d74387f4f2d57c520b2f4198d2ed193f1490ca11cd8n/a AgentTesla
2023-03-17n/aexe 6f24575f00c2dac29c50dd95998b4f9dcb21a179bf26a428638cdd78d69e1c49Virustotal results 55.07%Loki
2023-02-03n/aexe 526418af31a5d19ca68606c09913d4a88b0478f2b35bd6779c566ecaf84ab6d2Virustotal results 31.43% AgentTesla
2023-01-31n/aexe 5b62fd08b3a979449bc21a217e7057e710e5a66ab1f4159a935db45629e24156n/aAgentTesla
2023-01-25n/aexe 602d761e418caf11b04fb232198e42f6d1c2cd5dfedd56e7b1e858bb1dd5d0d0n/a AgentTesla
2022-12-15n/aexe 98bf2d56d6648be19d20e78cc7f006b4ef48c5627c2e9ce70539b5a51fc9e5adn/aFormbook
2022-12-12n/aexe 91fc06743f28fe6510f6e23c02532b67519f6bdc4ab6f93c0aa14abb8225d60en/aFormbook
2022-12-11n/aexe ea0e0dd2d22f1bd79f1f9edf64a8f13bef9f2568137743442ec299558f91e638Virustotal results 32.86%AgentTesla
2022-12-08n/aexe dc99d626b36e12c70bcb745c3b7894eda7d7d7c788978eb5ba17beca18e995abVirustotal results 19.72%Formbook
2022-12-07n/aexe 48f2bd3a73d609a51d086a878519ec41cf99371ff1a71877187bbee896ae15cen/a
2022-12-07n/aexe 268552c2ffe8fbb6b8a2244ce2931ca115a4057d74bfb72fc7ba91b95d95ac63n/aFormbook
2022-12-06n/aexe ba9b013506b8a73739901db161488cb054b2e4c56bd81330ed21958e3a5d5c56n/a 
2022-11-25n/aexe 502eb45094080794e04e0db85d0a1844f268407bd310d5a631fd185eab11b39en/aFormbook
2022-11-16n/aexe b25992203e4726a62f383c16d1550d078ba4d4d9416e83ca174861943e6098edn/aAgentTesla
2022-11-10n/aexe ef31090ad1ea4e41775b66e546cd00d8bf13be0b0c14aaf37ed499c9e25e32dfn/aAgentTesla
2022-07-21n/aexe e62d5985262d7ce47fa0c8ccb2cbfbf46a5e5da3c4cbefbf3ae3222595ec3fdan/a Formbook
2022-07-20n/aexe 98bd1ad6fbedd36a402e3f138a1589af7f460d8544273578d287dcc6796547b6Virustotal results 39.71%SnakeKeylogger