URLhaus Database

You are currently viewing the URLhaus database entry for http://198.46.199.171/new/new.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1588345
URL: http://198.46.199.171/new/new.exe
URL Status:Offline
Host: 198.46.199.171
Date added:2021-09-03 07:58:05 UTC
Last online:2021-09-21 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-09-03 07:59:02 UTC to abuse{at}colocrossing[dot]com)
Takedown time:17 days, 21 hours, 57 minutes Bad (down since 2021-09-21 05:56:12 UTC)
Tags:AgentTesla link exe Formbook link opendir RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-16n/aexe 939e8448b44089c4b2a3a6baba9a6bb6a2363e9e01463369ba41cab0082dc3d2n/a AgentTesla
2021-09-14n/aexe 763b0f42585f948ef01775277a4fc152bcccc1f560cfd7d850e8dce25ba37ccbn/a AgentTesla
2021-09-10n/aexe 30d19151144595548be93a69eaea1545a17c5fdc10fac24a8a33b90a94961cd0n/aAgentTesla
2021-09-09n/aexe fd5f21eb43514ea369b950218aa051ce47242f445bbe352dfa30e2c7a2d83041Virustotal results 34.78%AgentTesla
2021-09-09n/aexe 9823226b876dfebe21c476a59f4938cb67292e761dc7c6029576fb9396e93842n/a AgentTesla
2021-09-09n/aexe 63966d1b4bc17072e8b301e7128fc033d25139f24d19f7533291bb3dbafef681Virustotal results 56.25%AgentTesla
2021-09-07n/aexe f2f27ff68581132e12375a80d81d19a9bd60652bb0f9d0834916441ca52ae921n/a 
2021-09-07n/aexe f235f5460a16f4b3f9458ac7e65ac7758018184c10ac365ab69016de098a1846Virustotal results 36.76%AgentTesla
2021-09-06n/aexe 12b4d5b703c8e2261c3fd995514959fa6cefb4cc2ed8ea409ddfc8353f2de741n/aAgentTesla
2021-09-06n/aexe 44314f582748496d3383922a5fb3bb0fcf1d373696b026e4e12623f919e8d49eVirustotal results 25.00%AgentTesla
2021-09-06n/aexe 534ac228e075bd7975dd05a0b672b0f70886fcdb800ee6c03e834d2999e78729n/a RedLineStealer
2021-09-06n/aexe 15529247d828b711183e271ab9092b3a42395abd0ff4432421c8d65371689353n/aAgentTesla
2021-09-06n/aexe 515aeac4841b51f4ef59ace6b939e49eb902b00c4bd2f7a0c433ac260448b93fn/aAgentTesla
2021-09-06n/aexe 8085213a555a814fef5abfbdea92f1e695780a6292807016dc1814f040ea8325Virustotal results 20.90%AgentTesla
2021-09-06n/aexe a3526fbde858c171cecad37674c1cc0a90f997cce6d2563d41dd0846607cdd85n/aAgentTesla
2021-09-03n/aexe d53fe06c8384e535b2dcf3c96a7fd724ecf48ee3f3b9060750ff309ddea39758n/aFormbook
2021-09-03n/aexe 0dbc727b9b089ce71ec32623629e0b3ceae94285d1588ac4580c9d987b1c4e09Virustotal results 25.37%Formbook
2021-09-03n/aexe da7eff90633f82c14d128a573e55c95694fa567bd983438f6e4080db739ab55dVirustotal results 28.36%Formbook