URLhaus Database

You are currently viewing the URLhaus database entry for http://185.28.39.18:7777/185.28.39.18/obizx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2712475
URL: http://185.28.39.18:7777/185.28.39.18/obizx.exe
URL Status:Offline
Host: 185.28.39.18
Date added:2023-09-19 07:59:05 UTC
Last online:2023-10-28 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-09-19 08:00:11 UTC to abuse{at}des[dot]capital)
Takedown time:1 month, 9 days, 14 hours, 18 minutes Bad (down since 2023-10-28 22:18:28 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-10-13n/aexe f9ea89e4a7f2ea6bb976c34859dd0ad3ba4b82edb969e41cd333fe3e8019b02aVirustotal results 25.00% AgentTesla
2023-10-12n/aexe e0096418b652e8ff5254e6b507e2d61d9350c1636d294d4f4b35acf343d1a5f2Virustotal results 25.71% AgentTesla
2023-10-11n/aexe 00867f3551c05c2c802258bd0446bc0d60e1cd6eb1a05a895ce816f514373fb9Virustotal results 41.67% AgentTesla
2023-10-11n/aexe fd4974ab82ca37f9c285663a934fab7f515eaf97038fde673cab552d41f7466cVirustotal results 33.33% AgentTesla
2023-10-11n/aexe d3250ddf26bb9a71c94d06f22345e5ac30959195923ed5ca12db747e6ab1e65fVirustotal results 27.78%AgentTesla
2023-09-29n/aexe 63ad94d4ee50e7edb7ca2125ea488538068aacd4d572be22fa140addf11631e6Virustotal results 26.39%AgentTesla
2023-09-28n/aexe 3fe30f952c7c21eb70e3cf64fd32ce2049aa4e627a9cd9b832611512797a49a2n/a AgentTesla
2023-09-28n/aexe 904c83f2e7ba3adedd1871a3f7412ff6f79005917b2a4f1d68c7d67fcef33e18Virustotal results 32.39% AgentTesla
2023-09-27n/aexe 61cc47b3cb29dd8c5a7830c772d78614a502a4f30bd749cbfb33dbc0ec23a069Virustotal results 23.61% AgentTesla
2023-09-27n/aexe 8f70a1d59e944e3d4d2bc0610b17a836458ebf3da16994abca99cf4e1a490f00n/a AgentTesla
2023-09-26n/aexe 0dbe841340b646a3082b69532d74a8a15e69308ca6b97eefc77650911a086216Virustotal results 20.83% AgentTesla
2023-09-26n/aexe 41cc6b21a34ebb0cca5df142329c119f922ffbda9bc6e2efa833ff759218137bn/a AgentTesla
2023-09-26n/aexe 690b63f7918a1b1bc81e2515042b12dcb9e8a06cc2169703b2837b09ecacae54Virustotal results 19.44% AgentTesla
2023-09-25n/aexe 17a0dddf6a21775ea02e2ac6578b3f7fc9b054d0c169e5c70fc0dd29e1d0cfc4Virustotal results 29.17% AgentTesla
2023-09-20n/aexe f7b392b1c127e2ff745de54d49329a44a7a9df84f598dfefbfb3775e8b65f6edn/a AgentTesla
2023-09-19n/aexe ffd7fc226ac862e9c9a944e35a73a151e1399595030a3826482e15bc82b5af92Virustotal results 29.58%AgentTesla
2023-09-19n/aexe 9b8d232557686b014c7d81422e07090548f11a2fa9750a7b8233286539b1a048Virustotal results 42.25%AgentTesla