URLhaus Database

You are currently viewing the URLhaus database entry for http://192.227.228.121/dan.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1371443
URL: http://192.227.228.121/dan.exe
URL Status:Offline
Host: 192.227.228.121
Date added:2021-06-16 10:04:05 UTC
Last online:2021-06-22 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-06-16 10:05:03 UTC to abuse{at}colocrossing[dot]com)
Takedown time:5 days, 22 hours, 4 minutes Bad (down since 2021-06-22 08:09:08 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-06-21n/aexe 27cbe0ee3ed2d3994d62ef21b9b2ebd3f929c5370336b16e96aef3a87b00fab6Virustotal results 48.57%AgentTesla
2021-06-18n/aexe 33c0bb5892946563ec82d3c92da0921f133c3f6c5c765beff3b517331599dc0bn/aAgentTesla
2021-06-18n/aexe c8e239d667073d5f1c575a8b1bf2e580435a492deb302a6cd81489caddb337daVirustotal results 21.74%AgentTesla
2021-06-17n/aexe c4895ab5970a72feb57abe9377a9888d5ed3e680f6f168e3be2842ad4e1d5423Virustotal results 25.37%AgentTesla
2021-06-17n/aexe afb96b1d87fecb75fbf08033cc3a1e0abda905d64d826c8e437ca964b4742e6an/aAgentTesla
2021-06-17n/aexe 8c307c641b294a9cb932fe6addfd84d04ebb1a3a889f5572be5c21a01932391en/aAgentTesla
2021-06-16n/aexe c50594e26bf475268109c2843864ef12acaead42dba369abbff672f2e0db55bfn/aAgentTesla
2021-06-16n/aexe aab5f4c72afc1c8f1beacb75eb3fa27dfd18e6d1e58e6a0c9f28222550c30af7n/aAgentTesla