URLhaus Database

You are currently viewing the URLhaus database entry for http://194.180.48.59/oceanzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2645338
URL: http://194.180.48.59/oceanzx.exe
URL Status:Offline
Host: 194.180.48.59
Date added:2023-05-30 06:40:07 UTC
Last online:2023-06-24 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-05-30 06:41:06 UTC to abuse{at}des[dot]capital,abuse{at}serverion[dot]com)
Takedown time:25 days, 3 hours, 37 minutes Bad (down since 2023-06-24 10:18:23 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-10n/aexe a6507c308d5a01cce561a7eac683e60661bbd9e5386cf9b7596ae35881cb00dbn/a AgentTesla
2023-06-09n/aexe cae995212082d8cc847c485236cd379d0c81ec20c90dec4c7df96a2d63c6de0fn/a AgentTesla
2023-06-08n/aexe c430676409dc18613a7e93dce322b5267a137b8f337586317ad8342811dc7164Virustotal results 21.13% AgentTesla
2023-06-08n/aexe 32858494af5f8ee5f49b7d67894800a340dab412adf1b4326059bb14916c8659Virustotal results 22.54% AgentTesla
2023-06-05n/aexe b9faeca9b50dfb57f5bca6fd5154a468ea97ac5efeda1bb23c3b0c8bd662bf5eVirustotal results 15.71% 
2023-06-05n/aexe 0003e2236acd50ebd8d0944c7dc10ba37478d8e44ea4b0b31a33771e105b1c1en/a AgentTesla
2023-05-30n/aexe d5e90ce1f8eb541722c1fca05abb1f729b7a886c44c9aa93b1477a6183c9476en/aAgentTesla