URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/petitzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2259321
URL: http://208.67.105.179/petitzx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2022-07-20 13:51:06 UTC
Last online:2022-10-17 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-07-20 13:52:05 UTC to info{at}serverion[dot]com)
Takedown time:2 months, 29 days, 6 hours, 39 minutes Bad (down since 2022-10-17 20:31:29 UTC)
Tags:32 AgentTesla link exe GuLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-08-12n/aexe dd8bbc896364567dc376c3c87eb43ff81f6454af7131f036f0550206527eed33n/aAgentTesla
2022-08-11n/aexe e718a26d28b953b347ef0a0c818c06259b30e3bc00ee555e19c50473d56a4503n/aAgentTesla
2022-08-11n/aexe 4e4bd03f1359ae30019829ea3bf7e8539e9aea0484d7c20713a1c244e04c852fn/aAgentTesla
2022-08-10n/aexe 2fa44967b36125e0f14b91ae8c29f31b3eda2ab5b519ff29c377cb3b94f3cda8n/aAgentTesla
2022-08-10n/aexe e3749637e6f40b023d1ba513ba8048ca48132dae8eaa6a271042f2920bbd1419Virustotal results 33.80%AgentTesla
2022-08-03n/aexe 9c1d57c670f7937ff8282a9f9dc7b0999dfe3b3983d4ab14bdaecf40821e4622n/a 
2022-07-20n/aexe 42ff703cc63bd080af259c63b1a79c62c280692dbc4c70282c4a1eba788f0287Virustotal results 23.19%GuLoader