URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/secikmerozx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2263999
URL: http://208.67.105.179/secikmerozx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2022-08-02 16:49:04 UTC
Last online:2022-10-17 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-08-02 16:50:05 UTC to abuse{at}serverion[dot]com)
Takedown time:2 months, 16 days, 3 hours, 33 minutes Bad (down since 2022-10-17 20:23:25 UTC)
Tags:32 DBatLoader link exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-08-18n/aexe ee2ced66adeccfe45722c49efd8b99fd032d0426ff74cd10fc1e182521431404n/aFormbook
2022-08-11n/aexe 3752b7276189f276a42e2ee99480c513f8a57554991644a98c7460671ec9d3c8n/aDBatLoader
2022-08-10n/aexe ba57ea61d7f33ee4e7ba9063e7a6b759076f9f511d57067e1d248882df65352an/a 
2022-08-02n/aexe f6b12f3c9ceb6b54a74b78981768d9d848884433b44b35a1c21d2632ca6eb784Virustotal results 26.76%Formbook