URLhaus Database

You are currently viewing the URLhaus database entry for http://194.180.48.59/pmexzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2638556
URL: http://194.180.48.59/pmexzx.exe
URL Status:Offline
Host: 194.180.48.59
Date added:2023-05-22 08:55:06 UTC
Last online:2023-06-24 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-05-22 08:56:05 UTC to abuse{at}des[dot]capital,abuse{at}serverion[dot]com)
Takedown time:1 month, 3 days, 1 hours, 42 minutes Bad (down since 2023-06-24 10:38:47 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-08n/aexe f5c29d2220a1134ebff767955e043ad273af49a44daf5a6e941cd96de8194b31Virustotal results 17.14% AgentTesla
2023-06-08n/aexe eb8b620a1c5c9d95076c740325ce3ea001a5e41e820f1d2a50b25d5ac16b2c38Virustotal results 21.13% 
2023-06-05n/aexe 611424dfb6c912df458e648a4571c42d7eae32d4cc2c5080ab4b948ee15c8c06Virustotal results 10.94% 
2023-06-05n/aexe 8a34b5d02da0ce27925fc0560ea3f210598f1c40c8918b4a130a1a75a17ec2e3Virustotal results 30.99% AgentTesla
2023-05-24n/aexe 893870940f0b3f56d46f71effcd3cc731607154214f1ba956f54f50b5a4134ddVirustotal results 29.58%AgentTesla
2023-05-24n/aexe f5c8db78887b77ac7d3293e8606ed0cdcfb045e1bdaefa2a19adc202a192ba08Virustotal results 25.71%AgentTesla
2023-05-23n/aexe da88ccb78b77682a6eb79e8ca1f8f5e5bf4c89e009158ee29a91bba96a175288Virustotal results 28.57% AgentTesla
2023-05-23n/aexe 692c0d768303a9109c25983469410132e0726ccc62069f6aed61ffd1f83137e4Virustotal results 25.35% 
2023-05-22n/aexe a7b03a792bf07eedf52b9d8ac326caed59c996becf7296287b4b7f3073c0ccabVirustotal results 16.90%AgentTesla
2023-05-22n/aexe 345750d39c7d8b5faf43e95d7621ab0ea56fbd219a78befa08b3ed5099540dbcn/aAgentTesla