URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/solutionzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2407806
URL: http://208.67.105.179/solutionzx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2022-11-11 10:26:04 UTC
Last online:2023-03-08 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-11-11 10:27:09 UTC to abuse{at}serverion[dot]com)
Takedown time:3 months, 27 days, 10 hours, 43 minutes Bad (down since 2023-03-08 21:10:48 UTC)
Tags:AgentTesla link exe GuLoader link RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-02-15n/aexe 11f15597d4147551dd935b1061313e7e96d79473e2d3229326c7cd0a0523164bn/aGuLoader
2023-02-08n/aexe 61878427cd1d8ae10265dc16cfa10444838db931e19429339fb5b7f44add7db4n/aRemcosRAT
2023-02-01n/aexe 2e6a8bb2fcfef5cdc29aa03bfe22b01ebe7b3f71e09ad302dec93d672d1c3141Virustotal results 8.57%RemcosRAT
2022-11-11n/aexe 5ce8c741c53218d7b27ffaa114a25412dea3000e0dc71af5f59b7fc937ff255fVirustotal results 50.00%AgentTesla