URLhaus Database

You are currently viewing the URLhaus database entry for http://2.59.254.18/_errorpages/lawzx.doc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2695832
URL: http://2.59.254.18/_errorpages/lawzx.doc
URL Status:Offline
Host: 2.59.254.18
Date added:2023-08-02 08:52:03 UTC
Last online:2023-08-23 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-08-02 08:53:07 UTC to abuse{at}icxhosting[dot]com)
Takedown time:21 days, 1 hours, 17 minutes Bad (down since 2023-08-23 10:11:00 UTC)
Tags:AgentTesla link doc Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-08-17n/artf 940387888527e0efd604a126935a6174423ce34d15dc1fd7b7c894b78985ad71n/aFormbook
2023-08-16n/artf d5c838bad4a67a31d6d4dfdddb394ee475af925ac9df985995eae5de8429b991n/aFormbook
2023-08-15n/artf 1768eeca3dbf15b17955ec2e16702f1d3b39f79420e2c218c5f53019d85680cfn/aAgentTesla
2023-08-10n/artf 5aebac92125547ec3d79dac08bf20e1a990758cf2bace37672dca5adfe509aabn/aAgentTesla
2023-08-09n/artf 48bc303529276d86909f2523bec585d5a7bf257f377aaef3f57dc6279a57e415n/aAgentTesla
2023-08-08n/artf 757e76e77538b5076603e3dd7f45cc9931ffcecae25b02364f60f6295bc5d1b1n/aAgentTesla
2023-08-03n/artf 8972f88f545848efde365259eb058edea0d7db003df9d83d4696ecdaf7618bccn/aAgentTesla
2023-08-02n/artf ed248657afc15600a6b8e5b9cfa94203f9bfeda0ebd1a3007356e99836adeddfVirustotal results 45.76%AgentTesla