URLhaus Database

You are currently viewing the URLhaus database entry for http://185.28.39.18:7777/185.28.39.18/spacezx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2712816
URL: http://185.28.39.18:7777/185.28.39.18/spacezx.exe
URL Status:Offline
Host: 185.28.39.18
Date added:2023-09-21 06:07:05 UTC
Last online:2023-10-28 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-09-21 06:08:05 UTC to abuse{at}des[dot]capital)
Takedown time:1 month, 7 days, 16 hours, 28 minutes Bad (down since 2023-10-28 22:36:17 UTC)
Tags:AgentTesla link exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-09-22n/aexe 9f6a0a2b53723a6670b45c75d032423bcd56aa6a89f377f5a1ceb442a231d25fn/aLoki
2023-09-22n/aexe 93f4ba21d3b855e192770114d08d89c2d0b8d196c701827cd2a1df5ffc66af49n/aLoki
2023-09-21n/aexe d035e1f50f58c92992d6791f1213c732919b198dc48399612b192737ff3412aeVirustotal results 29.58%AgentTesla