URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/coachzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2406008
URL: http://208.67.105.179/coachzx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2022-11-09 16:57:04 UTC
Last online:2023-01-19 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-11-09 16:58:09 UTC to abuse{at}serverion[dot]com)
Takedown time:2 months, 10 days, 23 hours, 45 minutes Bad (down since 2023-01-19 16:43:25 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-28n/aexe c697a61a5e82540256e0b2fa7aa142e69e65921c2baf8fea01f2522cb36663dan/aAgentTesla
2022-11-22n/aexe 2e46a9df0d410d5cbe7c5bed967108f6dc846b01a25863be99e30b2729a6fad9n/aAgentTesla
2022-11-16n/aexe cff0490d0ccd2e536f54bcfccde05e477131e6b3cd802f1e99bd3a11f46a8001n/a
2022-11-15n/aexe 0fb9bc318848997e7e3c7e2c46e5ca2cd08cb5436f162cef7ca9443802eebd63Virustotal results 27.78%AgentTesla
2022-11-15n/aexe 0fb9bc318848997e7e3c7e2c46e5ca2cd08cb5436f162cef7ca9443802eebd63Virustotal results 27.78%AgentTesla
2022-11-09n/aexe de48615b4961f21a958850a9869139d5c1b44d29e11b2a7164ea3e7e0071e930n/aAgentTesla