URLhaus Database

You are currently viewing the URLhaus database entry for http://194.180.48.59/obizx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2641530
URL: http://194.180.48.59/obizx.exe
URL Status:Offline
Host: 194.180.48.59
Date added:2023-05-26 12:12:04 UTC
Last online:2023-06-24 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-05-26 12:13:04 UTC to abuse{at}des[dot]capital,abuse{at}serverion[dot]com)
Takedown time:28 days, 22 hours, 49 minutes Bad (down since 2023-06-24 11:02:51 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-23n/aexe eb9013c343ab4b99b91861620223802a978910ccc099ecabe8b3a00bb59c6309n/a AgentTesla
2023-06-22n/aexe d019bc9b8c0bd6b5510d725027eee6ecea4f831cc63a7238785d93d6282fa1ffVirustotal results 29.58%AgentTesla
2023-06-21n/aexe 057b5a69c942a24a0fc9818ea3d08c6479ef6af994938f9023b50b952f8186b6n/aAgentTesla
2023-06-21n/aexe 5055a2248b9f1f6ae561b3c7fb6ca2f08b057f568dc70dfadc23d5ebec21a8e6Virustotal results 54.29%AgentTesla
2023-06-14n/aexe 2d1f6e9c74a38ef216403f61048d294090f9cb70f4134c2d2be419657ac3c5bdn/aAgentTesla
2023-06-13n/aexe 0b69b9b28e52ca7c557e411e484e36d4911485fefe19440bf62619f1cd51bcc8n/a 
2023-06-13n/aexe cc921e0670b63842cf917e784f2a32d0419defe2447a15d0a3ec396cbcdc07afn/aAgentTesla
2023-06-12n/aexe aceea30675a0a44b4efad41f7321aa4c5ca66baa1ddb805f4cc12df821bd1775n/aAgentTesla
2023-06-07n/aexe 0f919e6ede18cce5cd736b1fcae63545119a886f62c6d2ec6c029d05619f97b9Virustotal results 23.94%AgentTesla
2023-06-06n/aexe c6021b0eaa95a92d7546b5943a74fe64022baef337409a0f9baa21e0e5217e91n/a
2023-06-06n/aexe 3bdc4fb579dbfd37752bafc023e9eaaf2788ad91afe542f8d86e097e5ca62176Virustotal results 23.94%AgentTesla
2023-06-05n/aexe 1e5d17deff3fa956f261db951189431271b72b7654fce518153f0bba3768da4dVirustotal results 19.72% 
2023-06-02n/aexe 8235377c714eb9e58b2db6d39c4091d4b610296e8bfdfae466a8f286e655dabeVirustotal results 22.39%AgentTesla
2023-06-02n/aexe 8e4a644ab5ad02854fef51a8167107c8b5bd4fe503d8bf84fb08dc78fcd9f53bn/aAgentTesla
2023-06-01n/aexe a558acd6978677d1f7ea7e1a18f675d7a49b0c3216633b2aac042abc2d0a54afVirustotal results 19.72%AgentTesla
2023-06-01n/aexe a4407b972d1cb08cfa3307a6d595dba07c7c997eb470166d08deb68fdfb96f9aVirustotal results 28.17%AgentTesla
2023-05-30n/aexe f49567411601a3c9cc5dae7dfaea5ceb6892df63acea8cb6e3967d5d14c9b26fVirustotal results 18.31%AgentTesla
2023-05-29n/aexe 443bf4c67abdfcfa19422630a83facdbe366945ba39b62ca6261f81224787d80Virustotal results 17.19%AgentTesla
2023-05-27n/aexe 5e89509adc4e84bd594e09db8de73159a1541422f425d125cec1095329a38b0en/a 
2023-05-26n/aexe 75b154cf245787ef5077d51af20771c1c00d4beda8c768ccaafce426129554f0Virustotal results 30.99%AgentTesla
2023-05-26n/aexe ee2da73179620f58484c7ce7052675cdd0e12d05ba43d7d1d0cde21ef8260383n/aAgentTesla