URLhaus Database

You are currently viewing the URLhaus database entry for http://ri.ios.exe.webs.vc/petrol.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1566396
URL: http://ri.ios.exe.webs.vc/petrol.exe
URL Status:Offline
Host: ri.ios.exe.webs.vc
Date added:2021-08-26 12:22:12 UTC
Last online:2021-10-11 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-10-11 13:19:03 UTC to abuse{at}des[dot]capital)
Takedown time:1 month, 16 days, 1 hours, 6 minutes Bad (down since 2021-10-11 13:29:21 UTC)
Tags:AgentTesla link exe RedLineStealer link SnakeKeylogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-28n/aexe 538a93f2d650153a5469c61359f63c292843dedb0c3e856abb29b3b209a9430bVirustotal results 22.39%RedLineStealer
2021-09-20n/aexe 416d1974189d1e8078830a2e52bd899061ab2f97524a72cbbafc892234b359cbn/aAgentTesla
2021-09-06n/aexe dd2ca331624bbc4df5dd724114ae6c46766d79c75c3df4ff0c15d7b08d3088c0Virustotal results 19.70%AgentTesla
2021-09-06n/aexe 5a8550bd2fe9e9d67d5433a95e8fd069dde38b79027000dcd915bb0ca8c27774Virustotal results 36.76%AgentTesla
2021-09-04n/aexe 26eec3f200ba2c82704c7d26ac34b0ba7d29e2c3608fb1860d55bb7edf90abc3n/aRedLineStealer
2021-09-03n/aexe 3ed830ef9609f573a4a9ce7f0abc234f6cd226ba7a55bb8319cb1b47a0f2be7dn/aSnakeKeylogger
2021-08-30n/aexe 8e485fdd11df52204f1b88fcac9250e6dfd2bb8728d9393d40a4ad9731faf2e1n/aAgentTesla
2021-08-30n/aexe 156c21d06df1eff6f8779151dc74a7b785b8a696f90fb37b0b2655145949c74en/aSnakeKeylogger
2021-08-29n/aexe 64bf8a51999065f086c5b77dd7a6f567393bcc79e2d361e3d3a8f1d501b80040n/aAgentTesla
2021-08-28n/aexe aba57641d78a1a42badcc96adf738e022b1cf0b673e95bf6a47b4c8532ed98a5n/aAgentTesla
2021-08-27n/aexe be9589f2adcbadc925774b3b70cbdde42a8955d687ecfdc2018cbe0544e82a88n/aAgentTesla
2021-08-26n/aexe 11315440a031bde6b71c06799665cbd17e50bbdcd6d9e416b5ca3cef5d83151en/aAgentTesla