URLhaus Database

You are currently viewing the URLhaus database entry for http://79.110.49.21/agodzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2672619
URL: http://79.110.49.21/agodzx.exe
URL Status:Offline
Host: 79.110.49.21
Date added:2023-06-27 06:06:11 UTC
Last online:2023-07-17 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-06-27 06:07:15 UTC to abuse{at}sukhoi-su-57[dot]com)
Takedown time:20 days, 16 hours, 20 minutes Bad (down since 2023-07-17 22:28:02 UTC)
Tags:AgentTesla link exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-07-16n/aexe a4fc086a6ee943665825c08590dab011a51032294eed1c7971bb5bd9308868fbn/a 
2023-07-14n/aexe 6666bd3cfd70f1e45584b1a6ff5820e2717e177d32ed196201306ef99c957cc7n/aAgentTesla
2023-06-30n/aexe 53e575805dc9d69c41f366e65946a7d4adf051f322f463f70e9b2f80d50450cbn/aAgentTesla
2023-06-29n/aexe cd917c86fe27ecd3feeca690377817bce1f4034830e6d68a19dbffc8c61e97bbn/aAgentTesla
2023-06-28n/aexe 1d0cf9a5e034371075cf0a328d98c53f4eeb74325d61ee956222346ebb1f5497n/aAgentTesla
2023-06-27n/aexe ddcfb1ba424e8b10bc83301942845f50a4e5ada39250ba706a9ecbc7ee9e63e3Virustotal results 47.89%Formbook