URLhaus Database

You are currently viewing the URLhaus database entry for http://2.59.254.18/_errorpages/yugozx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2704671
URL: http://2.59.254.18/_errorpages/yugozx.exe
URL Status:Offline
Host: 2.59.254.18
Date added:2023-08-15 11:59:04 UTC
Last online:2023-08-23 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-08-15 12:00:11 UTC to abuse{at}icxhosting[dot]com)
Takedown time:7 days, 21 hours, 58 minutes Bad (down since 2023-08-23 09:58:37 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-08-22n/aexe 2fe8eab70a35d4a9846f15b24cbc32a07df75f246f6a699fdd53159e8453fcddn/a AgentTesla
2023-08-22n/aexe 6ccc7dd1538501f96244141ce239ccb239415beb46eaabd3ab03aef0b299b75fn/a AgentTesla
2023-08-21n/aexe a243d77faada9bc0e92165cfb7794a7da3a62c19b0c89f03a00b8c18b7f308f7n/a 
2023-08-20n/aexe 873affaacad199fcc1687b9d8e39d75707123ed4ce38181da37e093b624832dan/a AgentTesla
2023-08-18n/aexe ad79217dc98d23b4c3e99fe39b7a554671c5d13b2ea29a2013f8f86b2d904a07n/a AgentTesla
2023-08-18n/aexe 00d519c4aa56b27c8254ff7721e8dc31f9c3746afcced9380b3e6c532e0dc38en/a AgentTesla
2023-08-17n/aexe 29e9fcdaf070133121d5a2d5dcb5f4a4a25892e21c60e1d29a497ddaa8d54ea9Virustotal results 28.17%AgentTesla
2023-08-16n/aexe aed4ca29e0127320a814f0051b444338d8078cd79ee176c9db4a14c989dbf0c3n/aAgentTesla
2023-08-16n/aexe b3eefb7225c8437ba7e9c6800ffdc0f2bb42225246bc7cc4944ba343b40459dcn/a AgentTesla
2023-08-15n/aexe d88ca1dd2194d68703b49f6aeb18e8d2a08132d5f348b9d0cfaa96b90a87384dn/aAgentTesla