URLhaus Database

You are currently viewing the URLhaus database entry for http://2.59.254.18/_errorpages/obizx.doc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2695769
URL: http://2.59.254.18/_errorpages/obizx.doc
URL Status:Offline
Host: 2.59.254.18
Date added:2023-08-02 07:33:05 UTC
Last online:2023-08-23 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: JAMESWT
Abuse complaint sent (?): Yes (2023-08-02 07:34:05 UTC to abuse{at}icxhosting[dot]com)
Takedown time:21 days, 2 hours, 33 minutes Bad (down since 2023-08-23 10:07:19 UTC)
Tags:Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-08-17n/artf d99dfd92b5c40e3bceb1e79f0f8628f9b872d18062a7ff1e97cb395af0c9b381Virustotal results 45.76%Formbook
2023-08-16n/artf f3c2f3594817df1307afd458a0328ccff1e63683ef86a6d176ca41bda9e3a14fn/aFormbook
2023-08-14n/artf 79760a303d924139c197bd8cb810d63f93d4fc62cd2858dda1e33a1b3b54f197n/aFormbook
2023-08-14n/artf 1d8b6b8d9edc7442f293f31f633e9e3701a91fcae93bd4b5f3468c6f6595fd4cVirustotal results 45.76%Formbook
2023-08-10n/artf 3d05b9869dcf10fe7eba50fac1e81427d2699b5514ccf06b497830aef6b59c5bn/aFormbook
2023-08-09n/artf 545d40ade3522c1e3e361746d2575d0713ceb992658cb30cbca4d0cdc824e6e9n/aFormbook
2023-08-08n/artf 50d4047ceee0880eaafa9f27bf63914481f101c5e47fb8fe819a36362de036c9Virustotal results 47.46%Formbook
2023-08-07n/artf ae8912485487bbd99f7defde38ab0da19ed679c5eec9d0272ec8ea69fc7d191dn/aFormbook
2023-08-03n/artf 7604b60990297c5b6f34db41501c0297dbeac0f303377ccc92c4092579b2c846n/aFormbook
2023-08-02n/artf 00c631724740205bbd826f91c99aeffc142ab15b08b80416707989c2cf61edefVirustotal results 50.85%Formbook