URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/nellyzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2614338
URL: http://208.67.105.179/nellyzx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2023-04-20 02:40:06 UTC
Last online:2023-05-17 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-04-20 02:41:05 UTC to abuse{at}serverion[dot]com)
Takedown time:27 days, 8 hours, 34 minutes Bad (down since 2023-05-17 11:15:48 UTC)
Tags:32 AgentTesla link exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-04-30n/aexe a79e68bc2d8643ff603ce0333efb343924760abc43edcc450c124fe4b9142c75n/a AgentTesla
2023-04-28n/aexe 28c3fe7155927cb7482afbe59c25193a1a34856caa296cec11f9a3404df33d7cn/a AgentTesla
2023-04-27n/aexe 7428f76122fbba77322e7338dafb21a613cbcc104f5af85c026b350c2d426f23Virustotal results 28.12% Formbook
2023-04-27n/aexe 13f795b807d2a8f7f98f6c3fe33a46a849b401b555525047450a4490b2cd5ca5n/a 
2023-04-24n/aexe 2799249b9775bcf4a66a5f7fc52a40959815b1bb4b2b882b4f1e57d5dec406c1n/aFormbook
2023-04-23n/aexe c643ce9cf3045a605b3ed588dc7e992de791468c841013fcdb310e751b237ad3n/aFormbook
2023-04-22n/aexe fcb111870747765bbe1c5dfa321ddc77d97df0e3b99586438d35263d0dda584fn/a 
2023-04-21n/aexe df810d99cd1588f21a80f27dc691efb44083567f1385978dad10611858bad134n/aFormbook
2023-04-21n/aexe 42f2f917ae48fc7239e19745dadfc47fa16537798f75b11a21ba9a604fbb4631n/a Formbook
2023-04-20n/aexe 1238938e0503f03e6cae0bdffb27600e8128bdd3e93144a9b72d43dc7f78463fn/a 
2023-04-20n/aexe 896d0711b287b0914d88b93ff8d06623c60f45b405e12cbc34a406e09942a577Virustotal results 37.68%Formbook