URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/derekzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2401053
URL: http://208.67.105.179/derekzx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2022-11-05 01:43:04 UTC
Last online:2023-01-19 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-11-05 01:44:10 UTC to abuse{at}serverion[dot]com)
Takedown time:2 months, 15 days, 15 hours, 16 minutes Bad (down since 2023-01-19 17:00:20 UTC)
Tags:32 AgentTesla link exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-16n/aexe 246cf5a9a6e4c4083bdc2da2eb93a7afc4afd5a4d1b02f16e44adfae1a6c1173Virustotal results 26.76%AgentTesla
2022-11-16n/aexe 22ba7ba32d4ad6afea72eec478a9f5c57273f04a85d2d79651cdaa8cc615841bn/a
2022-11-05n/aexe 9c22f08fc1cbbb249b54adba03b6a03957cef4181c4161401085db2dd4383570Virustotal results 37.50%Formbook