URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/haitianzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2410676
URL: http://208.67.105.179/haitianzx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2022-11-14 13:31:04 UTC
Last online:2023-05-17 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: vxvault
Abuse complaint sent (?): Yes (2022-11-14 13:32:09 UTC to abuse{at}serverion[dot]com)
Takedown time:6 months, 3 days, 18 hours, 38 minutes Bad (down since 2023-05-17 08:10:57 UTC)
Tags:AgentTesla link exe zgRAT

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-09n/aexe fd9fa9cb1bf0d368eaaea92a5bacff9a75cf33bd6d2eed99d3e206a561c39716n/azgRAT
2023-05-08n/aexe 16e0f70aaf0cc2f3c42a4733756a09896247876b8f17e371c378f1ee4c0076d6n/azgRAT
2023-05-04n/aexe 0c061bd136d10cfde5a55c449ccaf331f3ce019856fdc290fdbb57428a5549e6n/a 
2023-05-03n/aexe 6b0840df51c220c650f4b92f4b20df9051a8ad1303e60e43a15cca53f4648e35n/a 
2023-04-27n/aexe 2f88611721df4cdcf150e14e5abea2c2c97e7ab5284e9e7488f310a486bc6561n/a 
2023-04-26n/aexe 72a22c106bbf53cdb479077dd6f7af1d022c915f63632ce1aabc86ccb828f1a7n/a zgRAT
2023-04-21n/aexe ffa35d0de350a04874c6d1ea8de26ad97f24457a5fdd9e4fb55d101bac25e2efVirustotal results 58.57% zgRAT
2022-12-12n/aexe 535f354af37bb4c50a9da6b4501ec483f2c6fc2fc2e5905677bc69e0c068b343n/aAgentTesla
2022-12-08n/aexe 770de70064348d681d3566ced39f477c786c50d2c267a4a045544b7339940a64n/a 
2022-11-14n/aexe f5502d191d45165f291e29f55529c53f764fced4cc156e940600d08936123c75Virustotal results 47.22%AgentTesla