URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/ahmedzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2556804
URL: http://208.67.105.179/ahmedzx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2023-03-03 15:33:04 UTC
Last online:2023-05-17 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-03-03 15:34:06 UTC to abuse{at}serverion[dot]com)
Takedown time:2 months, 14 days, 20 hours, 25 minutes Bad (down since 2023-05-17 11:59:23 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-03-21n/aexe a169b28aef17ec40410b335f295192681dc0eaaaa1b9f870f87efb009a83447fVirustotal results 28.99% AgentTesla
2023-03-21n/aexe 431d5ac94ffcc12e9ff48e227ba286736ba47a50e6afd8f1ac2d9bf4a1b9fd33Virustotal results 26.09%AgentTesla
2023-03-13n/aexe 7558016ac4ac085644fa7f85465e331a1764edbc8bcc5baa16779e5595d8d678Virustotal results 20.29%AgentTesla
2023-03-12n/aexe 7d0871fb8eb2f0655c0b25bbce8b37340870a539836fa45d05ff0466fbdb9bc2Virustotal results 30.88%AgentTesla
2023-03-10n/aexe 81e34f31c5bfb079cee0ba9562e3916f4eb71f1d043485e96449ecb2f40acc0dVirustotal results 39.13% 
2023-03-10n/aexe 52816c612e2ab0cd684dc1d411b5910be8b83bf29c3588eb4e734912507e1796n/aAgentTesla
2023-03-09n/aexe 46febfcae87e38090f7309c95f66902659f252615b7b983cc5b0cda09cb57964Virustotal results 37.68%AgentTesla
2023-03-09n/aexe 9aa18a5f80d0904cc5093766ff8c6258ddec5b83f1948e106b1b8b7c5331b8bfVirustotal results 25.00% 
2023-03-09n/aexe c8ba5e51f81d3dd26cd602e11009877af2497585c8b6845724cc0d6a84fa539fn/aAgentTesla
2023-03-07n/aexe 11113117a5262f41a4bbed276aec8faf760afaafbfd1c3c05e945aa1d3e911bdVirustotal results 21.74%AgentTesla
2023-03-06n/aexe c2f9b55d138def6ce13aee0438e44e97ea60199e1e707f57e42c625fb305764aVirustotal results 26.09%AgentTesla
2023-03-06n/aexe 7e0dd3b9557b18226181b4c0356499edd472030f975bcfc44a7fbfd56f7661a4n/aAgentTesla
2023-03-06n/aexe 9fe5448efcfb0a3d75204877140d9eeaa00ba0b84374742d1df5b03b6d41961eVirustotal results 25.71%AgentTesla
2023-03-04n/aexe 01d4c768eb131e8f7e2ffef8bc17f9ceb629ffdb3dd4a6364aaf8096bdd16161Virustotal results 33.33%AgentTesla
2023-03-03n/aexe aced5165801c3fae21fb69b21d9dbaea768a5cc075186c660a81685ceba0dc1bVirustotal results 20.29%AgentTesla
2023-03-03n/aexe 1e9b8c2056adf69d35b941a8514df02180ec6b2ff81ce8011023ba33ec2be203Virustotal results 32.86%AgentTesla