URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/starmoneyzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2381420
URL: http://208.67.105.179/starmoneyzx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2022-10-21 01:54:04 UTC
Last online:2023-03-08 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-10-21 01:55:11 UTC to abuse{at}serverion[dot]com)
Takedown time:4 months, 18 days, 19 hours, 10 minutes Bad (down since 2023-03-08 21:05:36 UTC)
Tags:32 AgentTesla link exe Loki link RemcosRAT link SnakeKeylogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-01-19n/aexe 290fc73136559c7231df2af03155badf2a1341c7742364bf8bc260b4d12c8aaan/aAgentTesla
2023-01-18n/aexe 4ec961389dcf825881ba0f1100d9ee32d5f7087e2337425d087fc0c5d768a990n/aAgentTesla
2023-01-18n/aexe 380e8ef71e8b771d0435a69f59fd4d8b938f40efd137d0adcd718d4cf707569an/a AgentTesla
2022-12-06n/aexe e6992fe30ded7015c62a4367943577a22594fc362417c1e9bfc42a8fe6de4e6cn/aSnakeKeylogger
2022-12-06n/aexe 1b1da45c6cff14f498bcae64c81ce606561f6d3035a7af6d3287c30307cd6c6cn/aSnakeKeylogger
2022-11-04n/aexe 77343d85a2df4dc88b4daa73bd066ad178f6154f22aed0249dd2f32517295d2en/a RemcosRAT
2022-11-03n/aexe 522de9141cf7d1449c48f439b23bbc53be3de244e1baf817759b64eedfe5ae00n/aRemcosRAT
2022-10-21n/aexe bca934140f58b1e4756419c9e9b5639fb8b49755cf5844348f06fb44e3a45595Virustotal results 45.83%Loki