URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/secbobbyzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2609917
URL: http://208.67.105.179/secbobbyzx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2023-04-15 15:53:05 UTC
Last online:2023-05-17 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-04-15 15:54:04 UTC to abuse{at}serverion[dot]com)
Takedown time:1 month, 1 days, 16 hours, 43 minutes Bad (down since 2023-05-17 08:37:37 UTC)
Tags:exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-04-28n/aexe 1cc3177fed347d062ce02a4f689d8f4e2a30dc4be68e933cfe1a95f0850a95dbn/a
2023-04-26n/aexe ceb8f84e52d2bda9f7916cbcaaf7437d65abd80ff0d3e218fcf863ca2895eceen/a Loki
2023-04-25n/aexe 3087fe9c3db24caf13c73e18becca5b44f588ca6552eef7f9309dd20f34860afn/aLoki
2023-04-24n/aexe a56d453832124bbc6d71058014f135fd211aa05e7d303f291005f7fe54b91bd8Virustotal results 37.14%Loki
2023-04-20n/aexe 3d716133c3c55ae857daad8b387cb60c20415b30664c3872be02f7c52d95b4ccVirustotal results 52.86% Loki
2023-04-19n/aexe 91915613722bd604df8cc3237fd4fce644cc1f161253831f0203be27f69ff2ebn/a Loki
2023-04-18n/aexe 12eee9ff3b20a56791bd4d11447e89fa30365e5aa212722868b85666230ec799n/a Loki
2023-04-15n/aexe 6de21eb1f1300e1b33206abb2a1af488f16305bc4be7265e17b5fc68b3cd2632Virustotal results 54.29%Loki