URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/uzomazx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2403539
URL: http://208.67.105.179/uzomazx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2022-11-07 19:12:05 UTC
Last online:2023-01-19 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-11-07 19:13:09 UTC to abuse{at}serverion[dot]com)
Takedown time:2 months, 12 days, 21 hours, 50 minutes Bad (down since 2023-01-19 17:03:57 UTC)
Tags:AgentTesla link exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-22n/aexe 903bfcbe2d85143ad723b47ed1edc96f5416fa3b584fe76e74d75e93ff4b2e64n/a AgentTesla
2022-11-22n/aexe af2338dccdb59d40b3e6fbde008f3fad793ae9910fc3f2210bf6e9a311bd8044n/aFormbook
2022-11-21n/aexe 196d9de729f6e43896227a330958dff99ccee0a3c629a5c890bdebfb21b4e2edn/a 
2022-11-21n/aexe 91ce6fe4bc141cb29ddcccf2e70719a92e6ef37d49734aaf10c5e88c2df6b3b3n/a 
2022-11-21n/aexe 5b3037db1a7e18d45d89a2d3f9c929636fef2c38f6afe4e24a7cc053f3be6f3en/a 
2022-11-14n/aexe 23c96a140db8d8bf5c14a2bf811ab8e22f93bf283179ebefeee31907b5067618Virustotal results 33.80%Formbook
2022-11-12n/aexe 68bfdeaeaaaf161478b30ca2c4583b56104def93d1b753ee8543c100ce06d70cn/a 
2022-11-09n/aexe 3c9009eeffcaac6b1e45e26ed3d7c399b42d9a9507cc56ddec477c399a3d9b2fn/aFormbook
2022-11-07n/aexe e61660e229f87b61562735d3d6f44326329b5d9e659198d02de592402984b7c7n/a Formbook