URLhaus Database

You are currently viewing the URLhaus database entry for http://185.28.39.18:7777/185.28.39.18/nellyzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2712469
URL: http://185.28.39.18:7777/185.28.39.18/nellyzx.exe
URL Status:Offline
Host: 185.28.39.18
Date added:2023-09-19 07:40:08 UTC
Last online:2023-10-28 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-09-19 07:41:05 UTC to abuse{at}des[dot]capital)
Takedown time:1 month, 9 days, 14 hours, 35 minutes Bad (down since 2023-10-28 22:16:24 UTC)
Tags:32 exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-09-29n/aexe 6ed8801868c8baadf89c50bff443e9c29002e0db951ee456ffba50bca1812d6dVirustotal results 26.76%Formbook
2023-09-26n/aexe 4fb330b2b5620e1b30a795ad5d989526d7cefbcb553d4a79227b1220351d25bdVirustotal results 23.19% 
2023-09-19n/aexe 5cf672b526f027b91466980510aa60c3a7f9bf5d086fa12b3a909caad278e022Virustotal results 30.99% Formbook
2023-09-19n/aexe 0e0c5ba817a732585fb0e4100c7c7fe60e35b389b941c1b6a975aeebff2c809bVirustotal results 27.14%Formbook