URLhaus Database

You are currently viewing the URLhaus database entry for http://2.59.254.18/_errorpages/lawzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2695833
URL: http://2.59.254.18/_errorpages/lawzx.exe
URL Status:Offline
Host: 2.59.254.18
Date added:2023-08-02 08:52:05 UTC
Last online:2023-08-23 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-08-02 08:53:07 UTC to abuse{at}icxhosting[dot]com)
Takedown time:21 days, 1 hours, 16 minutes Bad (down since 2023-08-23 10:09:18 UTC)
Tags:AgentTesla link exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-08-18n/aexe 04f9b267f0ce81017f3305ab8fbf4e1295336389cf7ec742ca1f8dcb4831cb02n/a Formbook
2023-08-17n/aexe c57dc032205e3bcbf86a8dc6053377976c6acc015a837fdb1c30f6ec8d37ab01n/aFormbook
2023-08-16n/aexe d1f88ae528bf7f14d38e798f0f8b4b2803ab815217625130df8343461dee9894n/aFormbook
2023-08-16n/aexe a0755b595474643bf1200cb8b3a9038f53d685b6caff8c82acf3ed344fa22da3n/a Formbook
2023-08-16n/aexe 3445cded48ec36b32cc7d8e5190e3d986063408a5d70bbfe507d5e3ba9dc6ba3n/a Formbook
2023-08-15n/aexe f9de5be5d337c16f6a3ad525011586ae0b14f04169e9b6ae61a35397a3311079n/a Formbook
2023-08-15n/aexe 126e048eed0b55d00c200460122394c059ad7e7fda97b0d52a97d478aa7b0998n/aFormbook
2023-08-15n/aexe de361195aca3d3d04494a26d2023ecdc0bf09cf56f379813d19b2c256ee18df8n/aFormbook
2023-08-11n/aexe a456a0fcdedef851458b225f6bae02f6ee4e9ff6e1d479376d3766497aea8ac2Virustotal results 26.76% Formbook
2023-08-11n/aexe 120efb48724487028465fb5d25db17b9398f56bad7116e54299ab5087104e69bVirustotal results 23.94% Formbook
2023-08-10n/aexe ca290a08560360e9090ea83a3f3916fd3db3d0c058bc7aa0ce349e8783b3ab23n/aFormbook
2023-08-10n/aexe 168e72097cea76b8d996b129c02d7a1d9825f72ecb193317d5f5ab08fef5540bn/aFormbook
2023-08-09n/aexe 344461b75267cd218101263f89187a2b1ab88db9391bcb9efb6e3fc9b871fb39n/aAgentTesla
2023-08-09n/aexe 57fb4bbec8340a3da56629716ef3716fa14a247aeef941bf37c052a815c1afc6n/aAgentTesla
2023-08-08n/aexe f7428bcecf7bcdf3d3fb1a8eca5b52e15fc8fd4c90077082c538c611d5b7f97dn/aAgentTesla
2023-08-07n/aexe 0924aea0baf47725fc3231386ee24a1ca0f290a8a2fad119b2348a5e3273daf1n/aAgentTesla
2023-08-04n/aexe 870fc4761da55ad6c3d881026048561e5b9538cf996dfd3661da3e066d2cbdb1n/aAgentTesla
2023-08-03n/aexe 8f5a454bd4b668404501cfc61cd1497ffbdd8decc69d2d043e0b58bcf038a397n/a
2023-08-03n/aexe 62ebd0e86e60df2f3994766589cf1b73d14dec9d6a4f6a07b120c6d39ecef2aen/aAgentTesla
2023-08-03n/aexe 746d3f266a1d6c17fd484a741cad28bb0578e63d235abefb6f949b90a1108a96n/aAgentTesla
2023-08-02n/aexe 4e8962c45fb4aa831a15ec2c5db19d6949c7426fa65ed3ed58ab794ad09e9f04Virustotal results 32.86%AgentTesla