URLhaus Database

You are currently viewing the URLhaus database entry for http://ri.ios.exe.webs.vc/petrols.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1566394
URL: http://ri.ios.exe.webs.vc/petrols.exe
URL Status:Offline
Host: ri.ios.exe.webs.vc
Date added:2021-08-26 12:22:07 UTC
Last online:2021-10-11 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-10-11 13:19:03 UTC to abuse{at}des[dot]capital)
Takedown time:1 month, 16 days, 1 hours, 18 minutes Bad (down since 2021-10-11 13:41:46 UTC)
Tags:AgentTesla link exe RedLineStealer link SnakeKeylogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-27n/aexe 538a93f2d650153a5469c61359f63c292843dedb0c3e856abb29b3b209a9430bVirustotal results 22.39%RedLineStealer
2021-09-20n/aexe 416d1974189d1e8078830a2e52bd899061ab2f97524a72cbbafc892234b359cbn/aAgentTesla
2021-09-06n/aexe dd2ca331624bbc4df5dd724114ae6c46766d79c75c3df4ff0c15d7b08d3088c0Virustotal results 19.70%AgentTesla
2021-09-04n/aexe 3aaec800b59847bf0d3f690efaaa5a33ae817e873c7a6b545ee00587dfc6b0e5n/aRedLineStealer
2021-09-03n/aexe 653f4885315b5fc96824b981288c337b68b4c437aad1543a2e044d274c97592aVirustotal results 42.42%AgentTesla
2021-08-30n/aexe bae6aa63d36a0a714752cbd48d486e7b585db8b8517f9afc98d55397cbafec8bn/aSnakeKeylogger
2021-08-30n/aexe fbe10985705a09416e36fe4bed6c63a58e7bcdcecec469f0c025ff6f5d09360en/aAgentTesla
2021-08-29n/aexe 8357ddd0adcd00a22b6c8d30af16c9e5d44014e98396d16ad336c4495e9b70a6n/aSnakeKeylogger
2021-08-28n/aexe a1ef7c34fac1d166d47f99112a77e8f00f229c78f3a248da9ef005387997001an/aSnakeKeylogger
2021-08-27n/aexe 8b906325a51619ed9e1917fc044755c0c984f4f94ad0917c04ac3f6144a19003n/a SnakeKeylogger
2021-08-26n/aexe 82bc5ee43ecf6f856d8580ff50eb03f0870eb8ba41032e5662228c25f161f540n/aSnakeKeylogger