URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/bobbyzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2264749
URL: http://208.67.105.179/bobbyzx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2022-08-04 14:53:03 UTC
Last online:2023-05-17 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: AndreGironda
Abuse complaint sent (?): Yes (2022-08-04 14:54:06 UTC to abuse{at}serverion[dot]com)
Takedown time:9 months, 15 days, 21 hours, 5 minutes Bad (down since 2023-05-17 11:59:19 UTC)
Tags:AgentTesla link exe Formbook link Loki link RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-01n/aexe 9846f06c53ac1c4b98ab94ae1db5d2b1e7e160d1c8bb9622aaa6fd471efdf4f7n/a Loki
2023-04-25n/aexe 12dc3dedf943f18e565b3c37f2d2eac8382fccdbd492bb710266b230bca288aen/aLoki
2023-04-25n/aexe b72c3f63e398549c2072002525e09f483c6c117a511d32774f66387d0552cc92n/aLoki
2023-04-24n/aexe 99785489b3e1cee3004a5f4fd2421ddfa773bfd1d023cbbd2f307f2846bbb318n/aLoki
2023-04-20n/aexe a3a76a33a4641ac3a8b6ebbc137ecf08c69be86d7a1d810754be57dd1f5baac9n/aLoki
2023-04-17n/aexe d8d96fb0f87869e18b2f527be9a50e08768896ae6df8df2311a71bac4281a1e2n/aFormbook
2023-04-11n/aexe 4669e3e29315d6c6a58e7911bb6776ce27ee9619261829b4f6c7d7c2d1c991aan/aLoki
2023-04-10n/aexe 222e95bb9306c62ed33d1385515aace6a020f71aecff8a3182b80a65d4861e92n/aLoki
2023-04-07n/aexe fc24072129c4b44e66d2397c15f4f52bc0a0907b944c89f64f2e0cac1bbcfae5n/a Loki
2023-04-06n/aexe 48e4129cdeddc10029a319310de7e4bd14804a38495dc424f8e5e09def0e8f47n/a Loki
2022-08-29n/aexe edd76f4398cd937c508d229a8482add54c2ec8efe84a6881af90bbd40d8b8601Virustotal results 27.14%RemcosRAT
2022-08-22n/aexe ba180ae6674d9daa2cbd08847130b5c39e82249838b3d7da09b3b2f67be526dcn/aLoki
2022-08-10n/aexe 41be1d666d2713c92100a830746c55b06ceffedcd0983895bcdfcee8827506b1n/aLoki
2022-08-04n/aexe e5097db57c0475b96c038290399f48135c5273c569aa476eb7d8b98c4b92c8f5n/aAgentTesla