URLhaus Database

You are currently viewing the URLhaus database entry for http://194.180.48.59/governorzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2638384
URL: http://194.180.48.59/governorzx.exe
URL Status:Offline
Host: 194.180.48.59
Date added:2023-05-22 01:13:03 UTC
Last online:2023-06-24 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-05-22 01:14:04 UTC to abuse{at}des[dot]capital,abuse{at}serverion[dot]com)
Takedown time:1 month, 3 days, 8 hours, 55 minutes Bad (down since 2023-06-24 10:09:19 UTC)
Tags:32 AgentTesla link exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-22n/aexe 987a4d7b9be473efd2aa0ff7f0958414d64e0fa058bbaadb702c2024dbc9562cVirustotal results 28.17%AgentTesla
2023-06-14n/aexe 51a584528b7e6df7d03d10134ee1b11fa8131a9c250141737da3fd8b598fab65n/aAgentTesla
2023-06-01n/aexe 007391d2d9045b56792ce040d658442ef6bebab5d5c60938c86a5835144a8d26n/aAgentTesla
2023-05-30n/aexe f98336b0cea5ed7b10aaf0b76b63d5f88cb61c2d492974a1fd22b8f1fb0b9e8bn/aAgentTesla
2023-05-24n/aexe c0cbe7aec17ef1a839c0344c4fe403684a7e90e89f105706c3d660cec8b2dc86Virustotal results 22.54%Loki
2023-05-23n/aexe ae7a207af9660222aa5f98c9344ef371121d8bc4ba6a3ec251d0c61ed6558238Virustotal results 36.23% 
2023-05-22n/aexe ff0557222bc5667c61d9751976b24c98bf06500af03cc4294d3b2f39815582adVirustotal results 69.01%AgentTesla