URLhaus Database

You are currently viewing the URLhaus database entry for http://194.180.48.59/jawazx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2638378
URL: http://194.180.48.59/jawazx.exe
URL Status:Offline
Host: 194.180.48.59
Date added:2023-05-22 00:55:07 UTC
Last online:2023-06-24 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-05-22 00:56:05 UTC to abuse{at}des[dot]capital,abuse{at}serverion[dot]com)
Takedown time:1 month, 3 days, 9 hours, 12 minutes Bad (down since 2023-06-24 10:08:45 UTC)
Tags:32 exe Formbook link RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-21n/aexe 1d24effbb1519b3eb68a88edae7bea4f42e974fe5c9cb4c11496c25b7ccf1e87Virustotal results 37.14%Formbook
2023-06-10n/aexe 2968df5307f5f87cf57d3f470edea04d1fad9b3a60426e59bbaccd5ab0b0a543Virustotal results 45.71% Formbook
2023-06-09n/aexe e3df1d7b18079e9928d68858263dc5abf9b274ebb59224d4ce38811966201cd8n/a Formbook
2023-06-07n/aexe 39b849f9f03f5eceb4f0ec1bb9ddfaa13c7fd1369871676ee9a60cc45a7997a4Virustotal results 28.17% 
2023-06-06n/aexe 552f2edef992972907f2e3067637779d976661581bb0682875471792509f0be7n/a 
2023-06-05n/aexe 1e56ba220b756c4cc64d0583e7a04511851f108b0046f5a4eaa3fb8d0e74c6e1Virustotal results 15.49% 
2023-05-22n/aexe 98e8a76487a5811e1dd8574c08a8b66dc39506044045fc8c994e5d0e533a663cVirustotal results 25.35%RemcosRAT