URLhaus Database

You are currently viewing the URLhaus database entry for http://13.114.247.134/winhace/orgd.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1105065
URL: http://13.114.247.134/winhace/orgd.exe
URL Status:Offline
Host: 13.114.247.134
Date added:2021-04-09 12:51:06 UTC
Last online:2021-04-12 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-04-09 12:52:02 UTC to abuse{at}amazonaws[dot]com)
Takedown time:2 days, 17 hours, 43 minutes Poor (down since 2021-04-12 06:35:13 UTC)
Tags:AgentTesla link exe opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-04-11n/aexe 36c5c91ad9faeed3bbd7bf576aca9d4a5c040d802a521584cd094776e61320can/aAgentTesla
2021-04-10n/aexe 9f693db7614129ee50af1b6765fe78ae1d319e6aa19f3e675a79c72df0520ad1n/aAgentTesla
2021-04-10n/aexe 6dc8a34aece4d4250886f68c18a406e216a82886e2e34d8d8c6983bb9989591dn/aAgentTesla
2021-04-09n/aexe 418a675c64aac0ba99641f5a7fcd5fa14af962e19626c4f5921c5fbad870c93cVirustotal results 37.14%AgentTesla