URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/zangzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2429606
URL: http://208.67.105.179/zangzx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2022-11-22 09:29:03 UTC
Last online:2023-05-17 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-11-22 09:30:17 UTC to abuse{at}serverion[dot]com)
Takedown time:5 months, 26 days, 1 hours, 21 minutes Bad (down since 2023-05-17 10:51:59 UTC)
Tags:exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-04-21n/aexe ca7c9acbed27dce340dba222eab6d86cde65549c636fcf42bfa497baed8edc76n/aLoki
2023-04-21n/aexe 55fd1b3c7d2846e3877b9dc4cc5b78a89415ed66335d93c5bdf6fee4309832efn/aLoki
2023-04-20n/aexe 1aa1a9e5b07f7e5a5d4cfb16aaadd4a68e2bd76c42f96e932396ccc8d5f18785n/aLoki
2022-11-22n/aexe 3ca0370032a82c1c1ee13e88727bd0763365b1731cc0d10934fe37f7ef949865n/aLoki