URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/heimdallzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2406788
URL: http://208.67.105.179/heimdallzx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2022-11-10 10:54:04 UTC
Last online:2023-03-08 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-11-10 10:55:10 UTC to abuse{at}serverion[dot]com)
Takedown time:3 months, 28 days, 10 hours, 50 minutes Bad (down since 2023-03-08 21:45:44 UTC)
Tags:exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-01-17n/aexe 3fc3939a2fc6d4c3fca7f8a09523c19052dde1cc175d80d03cd9f54e3543111bn/aFormbook
2023-01-16n/aexe 22471245b769519d4b63089e4fe8d3f2c098572cfd715ca85b581f087344b519n/aFormbook
2022-11-17n/aexe 329bb5f9474791002d8542ca8043544387e0f832b8253fbfa564c57a3563dea8Virustotal results 18.57%Formbook
2022-11-10n/aexe dc18df47b5b99206344abe7dc551b531f134a14e7f8c3390fb419167ce435f01n/aFormbook