URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/brucezx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2395312
URL: http://208.67.105.179/brucezx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2022-11-01 19:37:04 UTC
Last online:2023-03-08 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-11-01 19:38:11 UTC to abuse{at}serverion[dot]com)
Takedown time:4 months, 7 days, 1 hours, 36 minutes Bad (down since 2023-03-08 21:14:39 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-01-26n/aexe 216509ca0f82c10daa1b7ea155f150766effa1270b1cc4d946f7b6d26851f092n/a AgentTesla
2023-01-25n/aexe f711597a4eb7c26df4f434b6ba92ba617918340e1fafcf106aadfb0ff4902775n/a AgentTesla
2023-01-24n/aexe 55c1fcdd14707d2b66e77369d58508feac2b3f528d9369cda052faab6a921376n/a 
2022-11-09n/aexe 89eebbc30f01ee4b99d457ca5c7c5b3514f9e69c57792e9a29d77333b33d9ba4n/aAgentTesla
2022-11-08n/aexe 0e259105a3b2dbb7de38f7c9257504c810b3ed757d06952b3e55b91ef80e5721n/aAgentTesla
2022-11-02n/aexe 5da64e1746667364ade20610d6e1211e7a582d15e53ad69a339675ca626df391n/aAgentTesla
2022-11-01n/aexe fc770cf10f538ed1ee6db0d1bcb6d8119199acdc947730a56b10bf46e0dcb5ddn/aAgentTesla