URLhaus Database

You are currently viewing the URLhaus database entry for http://194.180.48.59/teambzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2649779
URL: http://194.180.48.59/teambzx.exe
URL Status:Offline
Host: 194.180.48.59
Date added:2023-06-02 05:51:20 UTC
Last online:2023-06-24 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-06-02 05:52:05 UTC to abuse{at}des[dot]capital,abuse{at}serverion[dot]com)
Takedown time:22 days, 4 hours, 34 minutes Bad (down since 2023-06-24 10:26:21 UTC)
Tags:32 AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-09n/aexe 062091e8dfcd454183cd27936fc78e170a8e52fd7229321ec40e912825e22684n/a AgentTesla
2023-06-07n/aexe cec5cc9dfa8e64cd0bacc6aa6f7767729dec65d6a8d53184b887dc89a6a76884Virustotal results 29.58%AgentTesla
2023-06-07n/aexe e4e0c637d5acac7d96749e87cc3921ca4b4f1248b09daaa5df22936c46613429n/a 
2023-06-06n/aexe edd9f03acb13176fc64b7b7136ce31c47297e109487ed25f15b6d1648609b28fn/a Floxif
2023-06-05n/aexe 0bd44f67d095b0b8c6b29dcb88b605943128a44245f1f9862adeba79a96682f9Virustotal results 18.31% AgentTesla
2023-06-02n/aexe 9e5c195dcf2739418a55f6d03c1a05507f533e8a226253ffdd8b93e96f9fea51Virustotal results 38.57%AgentTesla