URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/ugopoundzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2346138
URL: http://208.67.105.179/ugopoundzx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2022-10-03 13:56:04 UTC
Last online:2023-05-17 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-10-03 13:57:11 UTC to abuse{at}serverion[dot]com)
Takedown time:7 months, 15 days, 19 hours, 2 minutes Bad (down since 2023-05-17 09:00:06 UTC)
Tags:AgentTesla link exe Formbook link Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-14n/aexe 195b6bca9b1911720ff66c3bfc771a6fcc6a60a249303287966e1b2a29d6ecdbn/aLoki
2023-05-12n/aexe ab2a6d8a19bfcc2dbb53d35ffc5bf7e2a42bbfff73a044f5d3023186c6155cebn/aLoki
2023-05-12n/aexe d704399671c148012f96d89f1555c49706b08371cfc6348a6ec50bd230b69922n/aLoki
2023-05-12n/aexe 0f3ded82d31dc7e7692d4b70fa848ec00780412a2a94636ee7084bdfb1e0859an/aLoki
2023-05-08n/aexe ef5b1b236b415aa1d0c9b274ac2576ea0d9670b28ad93cfee6df4899d3d62b9en/a Loki
2023-05-03n/aexe dc6651da666d36a85f65708db6b9f514bda2eeadec8a4238fa784366459dbaebVirustotal results 32.86%Loki
2023-05-01n/aexe fb3a710751cc735af813b9d36d70e2d3a6c21f74985d67f5bf29b7c4966691c6n/a Loki
2023-04-21n/aexe c95eabd64c7bd54273fcee058c9af7b19d4183fe1c6745f2753bd1aac0bd3aben/a AgentTesla
2023-04-21n/aexe e4a0ae76726f36cba9f049d1c38fe9e0ace65ce45f7d331f8dd422e62696e072n/a AgentTesla
2023-04-21n/aexe ae0c4c5424ede6f7655b4f78bc82da56096b22de20ea41d5e5827a9a1ae8d538n/a 
2023-04-18n/aexe a13507bab73c2aa043a1b19a040cb034860a4fd24dd18a364bb2e6fada78695cn/a 
2023-04-18n/aexe b7186ddd6a153d6448e4a6e7d35b5f2d3b4ec619297299366e617beec34ee713n/a 
2023-04-14n/aexe 5e86212f51e61517dde3cc7d0c36b73a392816d73e18bd14d83b374bcf17ecf5n/aFormbook
2023-04-13n/aexe 17483ba2526d9ba490c29dc88e5c1a066b0c26f22243e02d312542a53f292393n/aFormbook
2023-04-13n/aexe 219242e65723eab87702eaa00e6e06bc076cff9b0b705e0ba72612d2f8d572d1n/a 
2023-04-13n/aexe f71b79ded797fcb2e8ee42cd11d559a485875bcaaf517d4e0b6b1a5b44121c18n/a 
2023-03-27n/aexe 6c8b93bdd0153dfe2c4ff9e4c758ec44f3e01fbb77cb54b51e7ed07efa734a44n/aAgentTesla
2023-03-25n/aexe e45adb38f46b6275c9208ffc10f5ad840da121078544fad3555ef8183608ddedn/aAgentTesla
2023-03-22n/aexe 8ab437ed1b348f24d6a58965cdc27a3e23cfc82fef4456bd3623f739abf196a9n/aAgentTesla
2023-03-22n/aexe 26e4169f450ad33d2ac91ed523a144039a75b295dd77493dd6b15bda5e7094f6n/aAgentTesla
2023-03-21n/aexe 0a3910d28d3f2f885f656070a26c9f7abafac1e5231c6b9a8e07844a833f6077n/aAgentTesla
2023-03-20n/aexe 745334ebcf459ec748d00eaf3bcb94045cebdd6275aca548255c1c922f0f9d9dn/aAgentTesla
2023-03-19n/aexe 4b789d5f408c471f685675f946acb8ad05d7c3b660037d12367af2f1e4e82bfdn/aAgentTesla
2023-03-16n/aexe 4978dbd8c40bff5c01fa888ff9523adb19b70efeabf9f1453ba293d2a5afdce7Virustotal results 62.32%AgentTesla
2022-11-17n/aexe 20bf9de191b51755f2680bebdce8ad9cb9a7d4b4563dfcfff257ddefd34665cfn/aFormbook
2022-11-17n/aexe 8a8f2a1703e3a3827fec8cb04106a7772d7d5e86ae30aea91fd3bb28607a1de1n/a 
2022-10-10n/aexe 21b6c106891664c90aa10bc3de63047ea28724c11efee30853d219638844fc5dn/aFormbook
2022-10-03n/aexe 6bbfa5ab7aa24cf9fe44b50930dc21142387d590c988004fdb0d3b40df3ed1fan/aFormbook