URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/rexzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2259318
URL: http://208.67.105.179/rexzx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2022-07-20 13:51:04 UTC
Last online:2023-05-17 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-07-20 13:52:05 UTC to info{at}serverion[dot]com)
Takedown time:10 months, 0 days, 22 hours, 19 minutes Bad (down since 2023-05-17 12:11:08 UTC)
Tags:32 AgentTesla link exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-04-26n/aexe 4e73f70ca9ca60dca6299bbe61d4645d655aadb66be172915069dc27e0918ce2n/a AgentTesla
2022-08-15n/aexe 28ca5dea8ca246a61d262c54081363c158312e46634bcf4b886358ee08dee89fn/a Formbook
2022-07-21n/aexe d524deece8493db69c10101c080269bbac5054a3d5740d21d50d536753df0c9an/a Formbook
2022-07-20n/aexe ee24a04b1dfb099dba9c6ea59d5225ad4f9a626d622475f5a77f2d325ff260b8Virustotal results 38.57%Formbook