URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/bozx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2395551
URL: http://208.67.105.179/bozx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2022-11-02 01:33:05 UTC
Last online:2023-03-08 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-11-02 01:34:10 UTC to abuse{at}serverion[dot]com)
Takedown time:4 months, 6 days, 19 hours, 31 minutes Bad (down since 2023-03-08 21:05:11 UTC)
Tags:32 AgentTesla link exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-02-15n/aexe d090c44183576f91fe07620b3863a338617eb3ee5629cc01c8a7b12a5093fae7n/aAgentTesla
2023-02-15n/aexe 396fb15afaa0e4cfaa51cbc1d122d3db5797c2bc16af8993c31019c9b3be26dan/aAgentTesla
2023-02-14n/aexe 54a7e0191d3c855394a316900d3a4c722c395ef1cdaea718ae4f7a7a709ff647n/aAgentTesla
2023-02-04n/aexe 144d9574facfd48b3d00779c8f9d8935b260e3c8dc07956877bd578aea7b0b5cn/a AgentTesla
2022-12-24n/aexe 2e4678d03a2fd534b0cb7387581a08ff198585090db19781d9dba94a0e7f860dn/aFormbook
2022-12-23n/aexe f3ad8adc8c285a87e6905cb1176c4cb234374ae634d6b3e47dd6392635c11a65n/aFormbook
2022-12-23n/aexe a29af58a3927ea2351cd47fc63cba2d51f1405ab931a9b4ce3679a455836da35n/aFormbook
2022-12-22n/aexe 93827cfecf4525a58bb7e1214ed62faf17d6b2831b0e7da4ce5cdbdecfbf2261n/aFormbook
2022-12-22n/aexe 6a8b8d64cdbdd6d21a4c56e47929c8dee133615149ef899342842fbbe910c2fan/aFormbook
2022-12-21n/aexe 2f737af2624feac70ecd09fc431e44685a9fff885822f2d463bf56ce8b3edffaVirustotal results 25.35%Formbook
2022-12-21n/aexe cefd4eb74016e610d635972a5c7131ef8f253b6309cbeb5a3db216b506ef2185n/aFormbook
2022-12-20n/aexe ed236ec0b877086ffbdd929f5beec3818c032744d9f088c45b3a348f5648d038n/aFormbook
2022-12-20n/aexe f1824fe41b4fb79b857d2a94537bae3a91a6056378f5aa1e59255ab3bbe7b21en/aFormbook
2022-12-20n/aexe b3a41dea7c4e14a4f0dbce7c76229121c97bcc0950ce35e59c27ca2cbe6b28a1n/aFormbook
2022-12-15n/aexe ada6fd59260f173840d2fd96915fd3f31f308c6c0b2f8d3abc86a06effc34c40n/aFormbook
2022-12-14n/aexe ba36ce9292b8dbe70a94cbbebd8c3ed21aaac80b1eed16883d25da8f56731560n/aFormbook
2022-12-14n/aexe 19a1020889f42ac59c040b985510efa28ab812edce9394f7f9cb7250a5d2c7a2n/aFormbook
2022-11-02n/aexe cbce721b186a5ebb1a2c51249571d8021cc67c019a0cfbc0cef73fd1de48708eVirustotal results 38.18%FormBook