URLhaus Database

You are currently viewing the URLhaus database entry for http://192.227.158.110/dan.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1598795
URL: http://192.227.158.110/dan.exe
URL Status:Offline
Host: 192.227.158.110
Date added:2021-09-07 06:14:05 UTC
Last online:2021-09-15 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-09-07 06:15:03 UTC to abuse{at}colocrossing[dot]com)
Takedown time:8 days, 1 hours, 9 minutes Bad (down since 2021-09-15 07:25:01 UTC)
Tags:AgentTesla link exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-13n/aexe a431eeda3e7918a02344db663f68ea51c8ffd8cc159d4bac8b41d13c79bea576Virustotal results 86.76% AgentTesla
2021-09-13n/aexe 782ab89eec73488d350824df9e27b0e7ec820c3aa3ac1f66a009b3b0c2cd2a43n/a RedLineStealer
2021-09-07n/aexe 407d5083a6daea935d9d8e0e6ab8506737c160b97138e34be0e52e1895a46073n/aAgentTesla