URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/xzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2264209
URL: http://208.67.105.179/xzx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2022-08-03 01:47:03 UTC
Last online:2023-03-08 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-08-03 01:48:05 UTC to abuse{at}serverion[dot]com)
Takedown time:7 months, 7 days, 19 hours, 7 minutes Bad (down since 2023-03-08 20:55:32 UTC)
Tags:32 exe GuLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-02-12n/aexe da7fdfd7e858d1a49ab0db23c9276e2180c43acedad4466fd1161f35e97036dcVirustotal results 50.70% 
2022-10-25n/aexe 8167beaf27ed4c8ec02e74cbd8dff7526063e0f69aab33fb276e100895b86113n/a GuLoader
2022-10-11n/aexe 7eda2332a7567c0d38dd69b6cbe9f6229f1d58250cbd1e500d0e3e2203d1a07en/a 
2022-09-14n/aexe a6338b8ba3792bdc4dd5ac71e16b17967dba102c879675a2d250fd5a7d4f45a7n/a 
2022-08-30n/aexe 962285e4858d88ccade3bfaef1db663eeac0a503791d2443ba187f014f16632cn/a 
2022-08-30n/aexe efb17290b0db81d91a5d7fea14710c2b915f08c009ce549e8a86e13d48303c4cn/a 
2022-08-29n/aexe 48a9ddf37f33829c5287d24472b0cd3c8d0d6cf3dd19347cb9ee1d8644d290ben/a 
2022-08-29n/aexe cddee28d53320a41c1bd4295a8a1808c452644cf217b7de9534046d0c42c75d1n/a 
2022-08-24n/aexe 491202ec3ed48b5b407e443afc94fb03388d03693d02ae2ff9cc738da4d27465n/aGuLoader
2022-08-03n/aexe c1d412945be7ae627b90fb6fdc3863ab510034e711a0e9309d8b5515d8422cd4Virustotal results 37.14%GuLoader