URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/undergroundzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2377928
URL: http://208.67.105.179/undergroundzx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2022-10-19 04:51:05 UTC
Last online:2023-05-17 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-10-19 04:52:13 UTC to abuse{at}serverion[dot]com)
Takedown time:7 months, 0 days, 6 hours, 57 minutes Bad (down since 2023-05-17 11:49:58 UTC)
Tags:32 AgentTesla link exe Formbook link RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-04-30n/aexe 33a6fc4cd3132b1cf65832aabb916973080c7fa1e8bf1f7afe667b3894b1ba55n/a RemcosRAT
2023-04-28n/aexe 44669f46e429f04523149ee80e287dc445e5834343020d9719175c69b46ccff1n/a AgentTesla
2023-04-27n/aexe e5587195f08e264d30442968beeaae93f3c244d50774292dfd1c28314011e787n/a 
2023-04-26n/aexe faf7feff3dc62ae783ececf47b79e7f9a82d5df8962691854b9d027895d2efaan/a AgentTesla
2023-04-26n/aexe a944f2939223251ec6312aaca9f4458fb56838cf1c169ac1fbead9201254f98en/a AgentTesla
2023-04-24n/aexe 88c57d68e2ca4a359aaf8a1d6225ce440657f02c27f2e87f61cf72d93b4ae956n/aAgentTesla
2023-04-24n/aexe a84ce871209f18192168c19b17bc3c0061aff83a98611828128a54fafde6d4a6n/aAgentTesla
2023-04-21n/aexe da381d1bd4b6604a3af5906814a431537463ea383b7a61b8e374c200bfaeba64n/a 
2022-10-19n/aexe 6034200b55579c47e45b1dbe648f71aa554ff6b0ab8637c5f1953db8572649c4Virustotal results 37.50%Formbook