URLhaus Database

You are currently viewing the URLhaus database entry for http://45.81.39.123/ezy.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2721582
URL: http://45.81.39.123/ezy.exe
URL Status:Offline
Host: 45.81.39.123
Date added:2023-10-17 11:05:08 UTC
Last online:2023-10-24 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-10-17 11:06:06 UTC to abuse{at}des[dot]capital)
Takedown time:6 days, 16 hours, 49 minutes Bad (down since 2023-10-24 03:55:23 UTC)
Tags:AgentTesla link exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-10-20n/aexe d144bbf6939936bbf1ecec2bc6068f7c56f10b66077b7a18e31f65ebbf74833bVirustotal results 19.44% Loki
2023-10-20n/aexe 3f1efc05d9d6a3f302c354bb0bf5802e258813d2cf6bb63bd2f8ead38df31bebVirustotal results 22.22%Loki
2023-10-19n/aexe 23efa6d954c72bf45f697459c8bc8f2ca9f523fa815a5b698d782b0c19431d6aVirustotal results 30.56%Loki
2023-10-19n/aexe 32fb7fb2351e7f85f2cf13e7810f533cf87723696fe9b256cadd3dd7d6e6cc7cVirustotal results 29.58%Loki
2023-10-17n/aexe c48248fb90e206349a782e77d256e3ea11fa13049a9f2047cb90f4eeb0e30eacn/aAgentTesla
2023-10-17n/aexe fec2fc59ff0deda9141200d10606ec0314a62f18a5b479e6438a13d8808d58caVirustotal results 40.28%AgentTesla