URLhaus Database

You are currently viewing the URLhaus database entry for http://194.180.48.58/obizx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2668248
URL: http://194.180.48.58/obizx.exe
URL Status:Offline
Host: 194.180.48.58
Date added:2023-06-21 06:35:08 UTC
Last online:2023-06-30 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-06-21 06:36:13 UTC to abuse{at}des[dot]capital,abuse{at}serverion[dot]com)
Takedown time:9 days, 3 hours, 25 minutes Bad (down since 2023-06-30 10:01:55 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-22n/aexe d019bc9b8c0bd6b5510d725027eee6ecea4f831cc63a7238785d93d6282fa1ffVirustotal results 29.58%AgentTesla
2023-06-21n/aexe 057b5a69c942a24a0fc9818ea3d08c6479ef6af994938f9023b50b952f8186b6Virustotal results 30.00%AgentTesla
2023-06-21n/aexe b939a54436fbf49a9e065f0807e9071f3c29772c38857dc98a999a916e5ad2e0Virustotal results 30.00%AgentTesla
2023-06-21n/aexe 60a044f19c29cd98a7b96ba2df345a58191e83a322297c03928d7adba38a4442Virustotal results 34.29%AgentTesla