URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/activatezx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2598337
URL: http://208.67.105.179/activatezx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2023-04-05 12:16:07 UTC
Last online:2023-05-17 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-04-05 12:17:06 UTC to abuse{at}serverion[dot]com)
Takedown time:1 month, 12 days, 0 hours, 20 minutes Bad (down since 2023-05-17 12:37:07 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-04-18n/aexe 75976b1d7ab35aee3b84e9180a6776247f0003041b98fb2ac8e99e46eeabd274n/a AgentTesla
2023-04-12n/aexe bfbf10e0e60ae847c7f5a2da040b161d78a3c8ef9b357158cfa92a9cff6da360Virustotal results 28.57% AgentTesla
2023-04-12n/aexe 62fa163e74b86a0ffa03a8aeb2126fca86f3440b0d17373346a599c45cbc720bn/a
2023-04-12n/aexe ee734d6d93d42624ffd7f363f3252ee46cfbc5b6adef174447232605bda7d607Virustotal results 18.57%AgentTesla
2023-04-07n/aexe ae64fb90225d89fc47da4f9759073771ec29788c66d87982c6dac4443d68a21fVirustotal results 25.71%AgentTesla
2023-04-06n/aexe 6c86a8df78c5e5290f7ff6183efa3aa88e81f9cfb796dc41f97b90ab55b0d4a8Virustotal results 34.29% 
2023-04-05n/aexe 1c016657f34ce6d4e22b93894605781f1315b462265588174fc9774f0013a519Virustotal results 20.59%AgentTesla
2023-04-05n/aexe 497406ab6755bb8957d596106d07297e3ec7000c5ae5de0b11e7dae6ae6b66fbn/a
2023-04-05n/aexe f2227038e0ff26cbcf040a694c1e6e0fd3c42316179c97eb539744aebc4ec0f2Virustotal results 28.57%AgentTesla