URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/obozx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2403225
URL: http://208.67.105.179/obozx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2022-11-07 12:18:05 UTC
Last online:2023-01-20 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-11-07 12:19:10 UTC to abuse{at}serverion[dot]com)
Takedown time:2 months, 13 days, 20 hours, 51 minutes Bad (down since 2023-01-20 09:10:18 UTC)
Tags:AgentTesla link exe SnakeKeylogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-12n/aexe 37322ceee0b4960b4b769389b2029cb0c39ee32750e5e39e20dacb483bd8e0a5n/aSnakeKeylogger
2022-11-10n/aexe bf3f5f542482832180adbb509fbe5d64df3fa6ccfd940d08f2c3f958a35ceb86Virustotal results 22.54%AgentTesla
2022-11-10n/aexe cbde753d6f1142e462255824434ffe2ecca02dced67a1987fdc9a6fd3dc8b6d8n/aAgentTesla
2022-11-07n/aexe 8e4ee0ec7d1ac518e6f583d03c62b7d89978f2a0df7f5d1e50e709fe7a91a512n/a SnakeKeylogger
2022-11-07n/aexe 4fa0b2f0de92f44a363b6dd07c8f3f43d336acc79891f41d88d5cc13b6566ea4n/a SnakeKeylogger