URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/donpyzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2612597
URL: http://208.67.105.179/donpyzx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2023-04-18 11:43:04 UTC
Last online:2023-05-17 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-04-18 11:44:05 UTC to abuse{at}serverion[dot]com)
Takedown time:28 days, 22 hours, 2 minutes Bad (down since 2023-05-17 09:46:34 UTC)
Tags:exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-12n/aexe 9bcad2bea581286ebd4302eb150125329a5927764de5c64264bc9daef332c379Virustotal results 30.43%Loki
2023-05-11n/aexe be0620cc8546300ed143e48934cdf5dd5fc4db596d1025f034517793f71e5e25Virustotal results 25.71% Loki
2023-05-10n/aexe 5476b336b77951457b9c5018e0e6e40e3be8fc38a628076d353d5a35edc921efVirustotal results 37.14% Loki
2023-05-10n/aexe 2d4abc06cfac67220aa879ecb76806a8d976d0740c3504500fd2c29dd7dc4c48Virustotal results 44.29% 
2023-05-09n/aexe dca1d0825cdbf98bf61db27a0f5c14862c9e339b9b3d52f3b7c671e5a76256ecn/aLoki
2023-05-04n/aexe 93dc3c7c8753d61d7849f608d7c5652e5868585f04ac69defcc7020d005b53d6n/a Loki
2023-05-03n/aexe 715b032282caa091a569892c6139bfa062e53ad7e37904fb3c57400fc1f494e0n/a Loki
2023-05-03n/aexe 46ec07717ba6bf115c3a3e2ab5b540379474ac1e9b0b5b0d553900b73fb6b255Virustotal results 32.86% Loki
2023-05-01n/aexe 707757a138c5245958298d580048297507e2c237df45a9707ad551cca8b4f550n/a Loki
2023-04-30n/aexe 3024c31fc46c7adcb52753e48a7af3f84dfd16121590761d7377ed14a12ce571Virustotal results 29.58% Loki
2023-04-29n/aexe ccd5dbde7f1824f906db4cec029c44ea3d4e0706702fd0f97bc73fe426c56d53n/a Loki
2023-04-29n/aexe f5742553830d66dcbe64103dd22c3481077d08db70dc4447ce50220d286255a6Virustotal results 27.14% Loki
2023-04-28n/aexe 0f782a18310e85fb4c6af94175693a695d75311ca863eb88382eb0ef833e3fb5n/a Loki
2023-04-27n/aexe 8e85dc2021de35b9e048c5ed12df5144d9a0c5fd9c79b221cd3d3976bdf5c0afn/aLoki
2023-04-27n/aexe 3a28ae767be7e7db2c34843c5bae4af2baa54017f75f4319be1907634b429144Virustotal results 32.86% Loki
2023-04-26n/aexe 7401a6e55be0e1b6e5a273dc735b248467aa6c9f97891991bad1e4efbeb21e0fVirustotal results 24.59% Loki
2023-04-26n/aexe b47bc4fcd3217ac6cda0cd4318054095dec027902001cd9541e2118bdcbc45feVirustotal results 34.29% Loki
2023-04-24n/aexe c830b8b6620385f0f7d3b090f4c38809d7ac37f013b9c1687e39e80564cc445dVirustotal results 27.14%Loki
2023-04-18n/aexe 5a9397f2ec2a6609708ad1bbbff41e1d6d099d863d0714003d35070be9786eddn/aLoki
2023-04-18n/aexe 3c55595857f8c19385e8e5ad4732797a409c113e2c6be94dba3a143c2dc4415cn/aLoki