URLhaus Database

You are currently viewing the URLhaus database entry for http://5.39.217.221/www/win.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1059531
URL: http://5.39.217.221/www/win.exe
URL Status:Offline
Host: 5.39.217.221
Date added:2021-03-10 17:26:05 UTC
Last online:2021-03-11 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-03-10 17:28:04 UTC to abuse{at}hostkey[dot]nl)
Takedown time:21 hours, 3 minutes Good (down since 2021-03-11 14:31:24 UTC)
Tags:AgentTesla link exe opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-03-11n/aexe e0fb429b066d2b97dde4465f957880b89d69bedfe92804f3952fd6d3898766f6n/aAgentTesla
2021-03-11n/aexe 9dab7d32a275a641bd167e1b375b12fd3e2e17b3ae7a12877cbcf5892add70edn/aAgentTesla
2021-03-10n/aexe 5b39249fdee4e9fa76ef6906990437c7529c0a8e1e6238606e8416f084d10972n/aAgentTesla
2021-03-10n/aexe cd8f366ed8acc9f614c93e81f7a8068c43ac8d8e42e2c7c6d37e7c2da994933bVirustotal results 23.19%AgentTesla