URLhaus Database

You are currently viewing the URLhaus database entry for http://198.46.199.169/ohms.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1583770
URL: http://198.46.199.169/ohms.exe
URL Status:Offline
Host: 198.46.199.169
Date added:2021-09-01 16:05:05 UTC
Last online:2021-09-21 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-09-01 16:06:02 UTC to abuse{at}colocrossing[dot]com)
Takedown time:20 days, 7 hours, 34 minutes Bad (down since 2021-09-21 23:40:52 UTC)
Tags:AgentTesla link exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-21n/aexe 3d21013ae42bc00a0c2a8b54a19370766f4a8b51e1a649e414504489cff18e67Virustotal results 23.88% AgentTesla
2021-09-20n/aexe 591e461d4d79a004fe1c9b1fa8681b29390c4b6cedf9ba561f26ec0e65700b92Virustotal results 20.90%AgentTesla
2021-09-20n/aexe 047484451678a12ca602c53bad24f1462d2dd56b96fc859d0f02799da623fc1bn/aAgentTesla
2021-09-13n/aexe ff471810287d9fc34b0015935d70abac091fd9ea7238164e9958029f1a5669fdn/a AgentTesla
2021-09-09n/aexe febeda610cbcf53b41619608a80a6129aee69d064d8ad5aa9c7b4c3a68ffaab8n/aAgentTesla
2021-09-03n/aexe dfb100697371119ee4e093d73c7c71a0a07c14bdc913f906f0f3cb57b287bbb5Virustotal results 23.88%AgentTesla
2021-09-03n/aexe 9525197c77e5de1094ea33c3cd76a3e87c91342b4d41148442808bc27b4e2ca6n/aAgentTesla
2021-09-02n/aexe ed6849e36e1a1df98b7957c684b3aedeb08674f12070ba105098364ef2c9f96dVirustotal results 23.53%AgentTesla
2021-09-02n/aexe ee0072bfa491f44ca7379ea10a57c49e384180abf7998f2f4a8b08d4fd24c176Virustotal results 23.53%Formbook
2021-09-01n/aexe 15500244e3dc1de0b63b0b8342380ae569510f3b932ae3c3ce8096bc7c1161eeVirustotal results 22.06%Formbook