URLhaus Database

You are currently viewing the URLhaus database entry for http://2.59.254.18/_errorpages/obizx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2695772
URL: http://2.59.254.18/_errorpages/obizx.exe
URL Status:Offline
Host: 2.59.254.18
Date added:2023-08-02 07:33:13 UTC
Last online:2023-08-23 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: JAMESWT
Abuse complaint sent (?): Yes (2023-08-02 07:34:05 UTC to abuse{at}icxhosting[dot]com)
Takedown time:21 days, 2 hours, 38 minutes Bad (down since 2023-08-23 10:12:57 UTC)
Tags:AgentTesla link Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-08-23n/aexe 0c1b29d6a3e60d8123578238430934ac886d91e49c0d144c4dfe0bc0417daa63n/a Formbook
2023-08-22n/aexe e514601779855b8797844efa8382cc84701a00615d5b2eaf8183780859140939Virustotal results 31.82% 
2023-08-22n/aexe 983a10a541a2e57e2640e77ad37e7ac4eff7286c1617e8ccc08db98418e00d6eVirustotal results 34.78% Formbook
2023-08-22n/aexe eac185bd1520eb8f6b6ff62d571549c5d073cd120e22119499c26e8515f0352en/a Formbook
2023-08-21n/aexe f6e3fd97082eec8433f618fdeab9af4b19999c9792dfc72b15cdbf4d87f2c279n/a AgentTesla
2023-08-21n/aexe 685b1a50bed0764f3d217be21183211db5b54517bb64b8e85b1bf83da98f21b1n/a AgentTesla
2023-08-21n/aexe 217a04102c6021e98815a35feab526e99a259f01c9baee3e143288dbc160b920n/aAgentTesla
2023-08-21n/aexe c64bc02b5836c20524a6c7f2bece244250500730f4d3e182c15f2d85a52a4cecn/a 
2023-08-20n/aexe aeef012a92829a9b258346f07cbcfc0dd4cf2840de7e95ebd69c09daa61b3806n/a AgentTesla
2023-08-20n/aexe 2f6ac7e19e69b8c29b1de9205fd6b839944722341616c447092b7df288bbb045n/a AgentTesla
2023-08-18n/aexe 80dd6624e723c71bda0bb04573a1e96662184bd5dbef76c824c884df8afa2e15n/a AgentTesla
2023-08-18n/aexe 87d39d5402d42c8e11f2013a362903be50510e85daca217160e3f9eee677a9d5n/a AgentTesla
2023-08-18n/aexe d441487af7e29ca8436cd75f0facc50100631560393c64d21429164f054b70c0n/a AgentTesla
2023-08-17n/aexe 781517d23af59280628d63e2f4bd0e34300ee94b8b6d353547b797e59b899edbn/aFormbook
2023-08-16n/aexe d26cfee8c2154130e5d6ff92e3c9a6a61259b25551894fa2d14326874d6da24en/aAgentTesla
2023-08-16n/aexe beb77b8e0cb4c171b691a90b4b60c80bc715793a5dedf3b97375d6d760f414d6n/aAgentTesla
2023-08-16n/aexe 5ac0d32f2c164f00048bf818f43ed4160be02cc98ec66c810d043fc77fc70929n/a Formbook
2023-08-15n/aexe 647b53eee8836897331690f3f9767826434802cc5ce9144668c7c23c3c6beb36n/a Formbook
2023-08-14n/aexe 681b4fb5d374583fa961ba8ad171585c0ba9d2e346c5fbb6fce92392a10a2d16n/aFormbook
2023-08-14n/aexe 5976276fb72cd6fca6b74ef6480cdfb439a14b8c52ab9e442b0ee85c130a5f08Virustotal results 25.35%Formbook
2023-08-11n/aexe 2f77d3d54d53abf393f64e11d858760760953897f4d10025cc4816b9b8b87e6dVirustotal results 21.13%Formbook
2023-08-10n/aexe 3f3d909a0b48ceadaf0b0d0d4afd89adeceb8eae53a112c57117e378bcda136eVirustotal results 22.54% Formbook
2023-08-10n/aexe 9d0a05a5f2cd9f4ab18c167ee94b33669992d74140a0d334e84eb1b2efd4e313n/aFormbook
2023-08-10n/aexe 4246ac35e29b03cf4057457231abf222b88bf64cd65b59d7dc79d35b1953372bVirustotal results 21.13%Formbook
2023-08-09n/aexe eb3bdf2cff8b5de8c911726f07eed2aa77a39ae01b21c0dd33aeab333a2be512n/aFormbook
2023-08-09n/aexe fa278261af3ab337d468f32853cbf7dc6f13bb529684f45d92a2069ee21318b4n/aFormbook
2023-08-08n/aexe e4b8b19c8c8fd39ae06ba2ec632970e7fe16f78ca1f91582461de5da1403a4edVirustotal results 30.77%Formbook
2023-08-07n/aexe 19f3d92b528afa72bfa9cd1f4b89b0cfc63b5cf0fef8d292ec957d853fe3b143n/aFormbook
2023-08-07n/aexe 03e156f16efbda2a891a6519a282ad085325d498695287ee92ad056f7d1c2422n/aFormbook
2023-08-04n/aexe 2e2f7d2ee122957844312161a09f0506d601b0ca7ebb31be40d7057d03627595n/aFormbook
2023-08-03n/aexe 62e9a0d6ea8553419fc15ae61ede5b23e2fbc4c555db4c1c5f819dd14e88bf24n/a
2023-08-03n/aexe fbfd173952479920e0f3a8aa41bdd2faea86d2de9a7080a023831e4769c94468n/aFormbook
2023-08-02n/aexe 2e43e75303476b0eff6585680ad006cc7a7506a4564aa49504512ee3b6621884Virustotal results 40.85%Formbook