URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/kayzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2397336
URL: http://208.67.105.179/kayzx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2022-11-02 15:20:04 UTC
Last online:2023-01-19 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: James_inthe_box
Abuse complaint sent (?): Yes (2022-11-02 15:21:11 UTC to abuse{at}serverion[dot]com)
Takedown time:2 months, 18 days, 1 hours, 50 minutes Bad (down since 2023-01-19 17:11:16 UTC)
Tags:AgentTesla link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-25n/aexe f7a85b381a8b14beb5b1ca19b4a3678c134970610a336376a0ad836191a130bdn/aAgentTesla
2022-11-25n/aexe 60c994d3d36e7f3acacb7d607b4efc3605315e6996f0380ac2d230c0f29a5e90n/aAgentTesla
2022-11-08n/aexe 721a2c8476cd98b41adde0731f745687e4a7619cadfcab95cb88915fa305aa48n/a AgentTesla
2022-11-07n/aexe 3fea3f6495a47986f614e1c2f360b959b3a0bd49bba695b7e06eeb6500fdd6cfn/a AgentTesla
2022-11-07n/aexe c93de97d06f5d4cf27825c058f39645b113083a3e6bd077071d92b1e6a2ae372Virustotal results 33.93% AgentTesla
2022-11-03n/aexe 63003a1d2a2681d119288b4cbdfa3e0b0248644336509b657e0fab1a4b364e8bn/aAgentTesla
2022-11-03n/aexe 9e4f0e0a10a778fb94e7631c17082b44bf75170d7ca81b393574fd3f4c004f47n/aAgentTesla
2022-11-02n/aexe 2c6f0cdc461fdb8bdf1f079f18f15338767ba7af10fea9fdbffb4bc21a742422Virustotal results 40.85%AgentTesla