URLhaus Database

You are currently viewing the URLhaus database entry for http://87.121.221.212/lawzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2688783
URL: http://87.121.221.212/lawzx.exe
URL Status:Offline
Host: 87.121.221.212
Date added:2023-07-24 07:26:04 UTC
Last online:2023-07-26 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-07-24 07:27:06 UTC to abuse{at}des[dot]capital)
Takedown time:1 day, 23 hours, 50 minutes Poor (down since 2023-07-26 07:17:27 UTC)
Tags:AgentTesla link exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-07-26n/aexe 1bf9eea6de3a59ee58e13e33175ffdd66c6ba4a187b4df949593853c43784afen/aFormbook
2023-07-26n/aexe 9c4729e8b07e00f05876ed556d5c27a993a60979374b7fdafe69c0aca66a7281n/aFormbook
2023-07-25n/aexe 1fbe5f912ec66d5c25ad0684a7fc431d87d9f04b47d45418d18821c1f29cdf06Virustotal results 21.43%AgentTesla
2023-07-25n/aexe e48249f3509fe6713162d4b093f75066b53d68e8df273bf4bc818f9939b64392n/aAgentTesla
2023-07-25n/aexe 5d47b03e4127869e2fd59a55a6f018b270dbfaaf78522077a8bd99b61e06dd17n/aAgentTesla
2023-07-24n/aexe eff9bbf602fab34b0fe063fb3595ef374fdeb30670db2eb04237a921f03ed47dVirustotal results 29.58%Formbook
2023-07-24n/aexe 216237da181e0a4fe72486534f4fb7694641a34508dce78b3d36acbd53bd9dban/aFormbook