URLhaus Database

You are currently viewing the URLhaus database entry for http://194.180.48.59/agodzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2649114
URL: http://194.180.48.59/agodzx.exe
URL Status:Offline
Host: 194.180.48.59
Date added:2023-06-01 15:17:05 UTC
Last online:2023-06-24 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-06-01 15:18:08 UTC to abuse{at}des[dot]capital,abuse{at}serverion[dot]com)
Takedown time:22 days, 18 hours, 55 minutes Bad (down since 2023-06-24 10:13:59 UTC)
Tags:AgentTesla link exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-23n/aexe 9e778ed10d6543b0b16f50bbb021181e2cd1d6e9ab230f28492eeb45838c3893Virustotal results 42.86% AgentTesla
2023-06-23n/aexe 83d3644a239ef9f0353c7387c55f76c1c5aa30eb1d261b5035aff03db365e9f8n/aAgentTesla
2023-06-22n/aexe 59084f9c3435606045261122fcece85c7dcff26b245657929a983e896b905405n/aAgentTesla
2023-06-22n/aexe 1c4c7802f3a6bcc8d0355ad3e5c482c0fcdcb79845733a5ffe5c081ef59241cbn/aAgentTesla
2023-06-22n/aexe 3034f4c4123e20d2d2306263c3fc0cf2ddd0b9ed15e480386d45c4550140233cVirustotal results 25.35%AgentTesla
2023-06-21n/aexe 996802dcddf7a2afc542a0d2eab92d8243a3126dd2f9a8c6e8cb9cebc09e8d61Virustotal results 32.39%AgentTesla
2023-06-21n/aexe 4d60f9998376b2059e5a19aa9337f44285cce66c0e6bf0535de18a87d3aaf973n/aAgentTesla
2023-06-19n/aexe 0d49707dd3dc7f33643c03ec81f9dc60fdacb43d47a577f3a80eb6ffd2851254n/aAgentTesla
2023-06-19n/aexe 27b6bc323ccafe9003f9e32c88dfa2941184070483de79a42f4c7f642e809e73Virustotal results 30.00% AgentTesla
2023-06-13n/aexe 852e0d9a8f474077261d053d587868b211e70eff320a7e7067c3fc1cb3253ea5n/aLoki
2023-06-13n/aexe 5db6a8dfafd6956beaf4127500cd5232d78d70165a1775fa1da58277a43327edn/aLoki
2023-06-13n/aexe 74c7307aa85a7a73d924dfcc7101941975b746d8d21b10e8807bf10ed19d3c02n/aLoki
2023-06-01n/aexe 9267fc3af8040cbf3f53d4501c063d70e54574c98d7133a5c18c8d5b9686d901Virustotal results 17.39%AgentTesla
2023-06-01n/aexe 813ee787efe7691b84a7286dfb567f0f6f377f3ac0f0d2dc200e106df9f8f222Virustotal results 28.17%AgentTesla