URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/psmzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2322914
URL: http://208.67.105.179/psmzx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2022-09-29 03:59:04 UTC
Last online:2023-03-08 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-09-29 04:00:10 UTC to abuse{at}serverion[dot]com)
Takedown time:5 months, 10 days, 17 hours, 50 minutes Bad (down since 2023-03-08 21:50:20 UTC)
Tags:32 exe Formbook link SnakeKeylogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-01-19n/aexe 6686886f6bde408da4c0157e50623721a3954c653127fdf40db52acecd969358n/aFormbook
2023-01-18n/aexe 3e677355817c5d7cf457b670c028523f420442374463e5aa23f5c195ae290472n/aFormbook
2022-11-07n/aexe dd20a13a29e7f556b64267a04b55f71f4a6b9ff2691854b04ffc939f57a27185n/a SnakeKeylogger
2022-11-01n/aexe ce49fe316e00aef70cce1d5430382613692b59d306b9b6253e88ac5c94732b0dn/aSnakeKeylogger
2022-10-31n/aexe c4bc99be2d00ad7e96c9f192f31da7d25c5971b3463b7f28f5a42659a4829ef7n/aSnakeKeylogger
2022-10-24n/aexe 9f622f9e683b289e978ef5a0c6b6069ac4d759e407658711158517efd39d9675n/aFormbook
2022-10-20n/aexe 8fc72b5ec8701ea1681ab2b170652cc65a43765657919f4fd104f967ff944e21n/aFormbook
2022-10-17n/aexe 68ff76201b38c3bcb3d3b69f07e0ecc617ecee29686cf64e2b7db4cddaea4a21n/a Formbook
2022-10-17n/aexe b9f43260c2f4f9cfbc4e48583716c602291104ee4ed0a150e981c0314dfe84b8n/a 
2022-09-29n/aexe dcb160b2fcab4bccf64b348b6225c4efe9266252ce5e2a3c39f8b7249886f248Virustotal results 33.33%Formbook