URLhaus Database

You are currently viewing the URLhaus database entry for http://2.59.254.18/_errorpages/stanzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2703716
URL: http://2.59.254.18/_errorpages/stanzx.exe
URL Status:Offline
Host: 2.59.254.18
Date added:2023-08-10 19:30:09 UTC
Last online:2023-08-23 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: James_inthe_box
Abuse complaint sent (?): Yes (2023-08-10 19:31:07 UTC to abuse{at}icxhosting[dot]com)
Takedown time:12 days, 14 hours, 44 minutes Bad (down since 2023-08-23 10:15:14 UTC)
Tags:AgentTesla link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-08-11n/aexe 9da5b7337f022a122afdd84c2744861da80dd7575f24c9a6abf9b00b2a0d2870Virustotal results 33.80%AgentTesla
2023-08-11n/aexe 2dd6ce65ea7d7e9e7ec4a5e52bcf41bd327e418c23f3851bea856d9490852e2aVirustotal results 30.43%AgentTesla
2023-08-10n/aexe 7f05f950858cd8ca08ed3841cb0bc540ee3d88c6ce3a360a89d42ffa7ce0ff2bVirustotal results 33.80%AgentTesla