URLhaus Database

You are currently viewing the URLhaus database entry for http://208.67.105.179/tmglobalzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2622845
URL: http://208.67.105.179/tmglobalzx.exe
URL Status:Offline
Host: 208.67.105.179
Date added:2023-05-03 01:51:04 UTC
Last online:2023-05-17 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-05-03 01:52:06 UTC to abuse{at}serverion[dot]com)
Takedown time:14 days, 5 hours, 17 minutes Bad (down since 2023-05-17 07:09:10 UTC)
Tags:32 exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-17n/aexe f4710268ff7f37d6884a54c7f599119bbd3b577ad0c1a0c1bb695f62ceccca43Virustotal results 21.13%Loki
2023-05-14n/aexe f60dfec6143b9281322904f2adb3787919478cce77e4f44c216f0b204f5a3fc9Virustotal results 38.03%Loki
2023-05-12n/aexe 9fdaae4a80674347e2b1fbbcb0c5b5270c66b9efa6dabf286ec4b79c07cee667Virustotal results 27.14%Loki
2023-05-12n/aexe 192156888112a7ea64ccd2f6f1cde0556f8656d2cce9623e3b9cc498b550f58dn/aLoki
2023-05-03n/aexe ae0d0c2a31f5fc59eb85300918c89dff9449822b197c41d35b372d57308aa9e5Virustotal results 42.86%Loki