URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/bellyzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2596566
URL: http://208.67.105.179/bellyzx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2023-04-04 05:57:05 UTC
Last online:2023-05-17 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-04-04 05:58:06 UTC to abuse{at}serverion[dot]com)
Takedown time:1 month, 13 days, 4 hours, 54 minutes Bad (down since 2023-05-17 10:52:44 UTC)
Tags:exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-04-17n/aexe a97d398040bb63c1ad86451ee043dfe518fc4a53a4415ea427a7a025a69888b5n/aLoki
2023-04-07n/aexe 9e12d1b00a03f422e969dc40421875b4b8de4504afe23c5dcc50ae31faf35337Virustotal results 21.54% Loki
2023-04-05n/aexe 62082dca80037bfed588756bdc0712791e9650eb9f2dd68a5b12d376fa70e13an/aLoki
2023-04-05n/aexe 35d73f1132978e70d922aed106443aaed23b9cc9d56a65940ca8f6242108c255Virustotal results 28.57%Loki
2023-04-05n/aexe e37c9f95987366f5222f9bf77421e6e3b81684f93eea9c1a947d29dc6210d98en/aLoki
2023-04-04n/aexe 88e7e6f23a45b8878b45a1beecb9152c88d715be23eb837f22ca8b5ca9a448b4n/aLoki
2023-04-04n/aexe 72291fd7befce6c37a8b6b8ad7b5b96a1b428356d365f7d3bdcd9c4dacce27c1Virustotal results 22.86%Loki
2023-04-04n/aexe 9c50fe80a314898db5b4849b8bf2523e6e943376a4832d1943d0c12d5e7d5b8dVirustotal results 25.71%Loki