URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/offbinzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2614335
URL: http://208.67.105.179/offbinzx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2023-04-20 02:26:05 UTC
Last online:2023-05-17 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-04-20 02:27:06 UTC to abuse{at}serverion[dot]com)
Takedown time:27 days, 8 hours, 44 minutes Bad (down since 2023-05-17 11:11:43 UTC)
Tags:32 AgentTesla link exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-15n/aexe 9b72403d8d0663158210961631adbc2b5574b89c249804edef87de56ab36c9b9n/aFormbook
2023-05-10n/aexe 908518191aecf6570fc10b1d299d64b2ac02f250fe17198a2407a9e12ddfcd30n/aFormbook
2023-05-10n/aexe 6eb965c0e3c30222e2d699318f653c0822eb0c955194ce234b9a01a1a05e4387n/a 
2023-04-30n/aexe 030c152d386b5849508a740eecad662de4e716ad593eb95863c93bb9be046a62n/a AgentTesla
2023-04-28n/aexe a85d2aa65e5b5d69769ff7dd1a63e90de9bd7f96a76fa96c52137587b63d1016n/aFormbook
2023-04-27n/aexe 62f8ee6fa76ecc7122e5abd0d792cc01a93da14bacd76d2585604165d6b9b9fcn/a Formbook
2023-04-27n/aexe 53450029b603a3050f6879652e7790433778678b4967fa340b83c6cdaab1ea5fn/a 
2023-04-26n/aexe f3cfdc0a51a37520ed715afd7a5a1311f30b8d1e55ee93cdbb6f25b44837de74n/a 
2023-04-25n/aexe e7c2b8fd0f30db376c2c5d18f6bdac1ee47c07c8201f70fda8c52d135d8a1b93n/aFormbook
2023-04-20n/aexe f641f1a87ee2a760b79417b410c52137c114e2618529bb90a0f281967975476eVirustotal results 35.71%Formbook