URLhaus Database

You are currently viewing the URLhaus database entry for http://87.121.221.212/nellyzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2676484
URL: http://87.121.221.212/nellyzx.exe
URL Status:Offline
Host: 87.121.221.212
Date added:2023-07-04 13:58:08 UTC
Last online:2023-07-26 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-07-04 13:59:07 UTC to abuse{at}des[dot]capital)
Takedown time:21 days, 17 hours, 20 minutes Bad (down since 2023-07-26 07:19:14 UTC)
Tags:exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-07-10n/aexe 4baa8f661ea6d1777e87005c1a5c2a73aae516037084f6318d3a13528f3a812an/a Formbook
2023-07-07n/aexe 63d155a4f290a050a6aa5169257f2351251a2ec814984ad4c146cff88524ca39n/a Formbook
2023-07-06n/aexe 27f929d67fb41a75387bfe20299a26444f8146ce09651fffe81db678018e6f3en/a Formbook
2023-07-06n/aexe a74e5824ef174a4cdff0bcdfdb4ce4705cc40dc20e6d8ffcf404d3cd7e50a67cn/a Formbook
2023-07-06n/aexe ed2689d4f89e5f40f8ddf93839da8b822d008329530090975edb6d0909bee67fn/aFormbook
2023-07-05n/aexe eff3b134c5b76bf812d5059eacb6370dfdc9b40b9164bec03682b136642bee2an/a Formbook
2023-07-05n/aexe a93a45529f730427dcf6bd7f124720338da6f5f74499204cc0fb73f460cfe0e6n/a Formbook
2023-07-04n/aexe b28c7e4510175a83aa87b5511c73319de27fc894ffc28d561d4689c3ca27d1f9n/aFormbook