URLhaus Database

You are currently viewing the URLhaus database entry for http://51.159.29.96/search/gefox.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3178702
URL: http://51.159.29.96/search/gefox.exe
URL Status:Offline
Host: 51.159.29.96
Date added:2024-09-17 20:32:11 UTC
Last online:2024-09-19 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2024-09-17 20:33:15 UTC to abuse{at}online[dot]net)
Takedown time:1 day, 13 hours, 35 minutes Poor (down since 2024-09-19 10:08:41 UTC)
Tags:exe Socks5Systemz link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-09-19gefox.exeexe c8b8fcbe4ca291f4a1b08258c4980bbe6323dda4f132bd1a6446324858d5d7e1n/a Socks5Systemz
2024-09-18gefox.exeexe 0ecc78c8637b4b28d7158a31ee3ca75f07dea64d7bb8c2330ce38189340a4c9en/a Socks5Systemz
2024-09-18gefox.exeexe a4d3e439ee171d55bfc435125503d421c2314d87e8bc5910161bebecfa505edan/aSocks5Systemz
2024-09-18gefox.exeexe ace8a2abb91d331c97259f9bcc0192e0493e6e243ea4e61c8516125ca9d5758dn/a Socks5Systemz
2024-09-17gefox.exeexe 8bc5aab9c43dafa763ecf0c4f4502980183b1a1560e8919397ac6ff32e144229n/aSocks5Systemz