URLhaus Database

You are currently viewing the URLhaus database entry for http://2.59.254.18/_errorpages/defounderzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2696868
URL: http://2.59.254.18/_errorpages/defounderzx.exe
URL Status:Offline
Host: 2.59.254.18
Date added:2023-08-03 06:56:04 UTC
Last online:2023-08-23 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-08-03 06:57:05 UTC to abuse{at}icxhosting[dot]com)
Takedown time:20 days, 2 hours, 42 minutes Bad (down since 2023-08-23 09:39:08 UTC)
Tags:exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-08-09n/aexe d38a6a6faeecb0d30b8d9a8d857e850f1f125dc1cfbe497899bd52695498bef5n/aFormbook
2023-08-09n/aexe 344b3c764a7075a0cdc2a9cd3f390c6b195fc0601077f68db9e8678a27c0c204Virustotal results 32.39%Formbook
2023-08-08n/aexe 63b0410652da12f415ba3be83cda769bd268b83000c425f666fbefb4fddbf3beVirustotal results 26.76%Formbook
2023-08-07n/aexe 185bc84b981c40e78829c220a28b4e7c431c2eefbac90d335b4a354986fa94den/aFormbook
2023-08-03n/aexe e5854984cb78e5ce4bcc31263e290d895b3de4660e87e0f5af115cb9b60b5500Virustotal results 40.00%Formbook