URLhaus Database

You are currently viewing the URLhaus database entry for http://192.3.194.242/EXCEL.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1635950
URL: http://192.3.194.242/EXCEL.exe
URL Status:Offline
Host: 192.3.194.242
Date added:2021-09-20 14:54:03 UTC
Last online:2021-10-24 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-09-20 14:55:02 UTC to abuse{at}colocrossing[dot]com)
Takedown time:1 month, 4 days, 6 hours, 47 minutes Bad (down since 2021-10-24 21:42:21 UTC)
Tags:32 exe NanoCore link RedLineStealer link Xpertrat

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-18n/aexe 9eea9caa338a673c1d88240839b08fe021ff9264620e7935ba5cb5bd3d00ebf6n/aXpertRAT
2021-10-14n/aexe f2926aaea4603961e15c9ac92eb599ddd51bd6e19bd7fded285a1db16753db87n/aXpertRAT
2021-10-13n/aexe 259dbea8ad36ca1f502f7eba9257bf7111313f4ef76c34922cd34dd5808b5181n/aXpertRAT
2021-10-11n/aexe bd5c24761ed0f7e6b1741abc9812e18794dd98524a7f4d3a8998d9a71af071adn/aXpertRAT
2021-10-07n/aexe 3e77ec2e0bbc394a1841bfb8f9b004f93fcbc35b401580abd01c92c41b6635aan/aXpertRAT
2021-10-06n/aexe 1a55b87ef779fe996b8aef3e98ea9252a5ce3a02d3a0a87000554bd41033a215n/aXpertRAT
2021-10-04n/aexe 9bd273556358606717f3d0e7d4a2521dba396d6838d8dfccb78bfc5c98590b84n/aXpertRAT
2021-10-04n/aexe 5bdc764598795f4afcb70f6ff95f29114f61ea24a1d836838125c08268e13de9n/aXpertRAT
2021-10-01n/aexe 9443d3d69b5e62fb2c944c1bc14b4d4ad21f3e0c70826b0d800e09eb9fb82d3fn/a RedLineStealer
2021-09-30n/aexe c830683f700f311fe3d533d849cf045b1cbed5ff76debaa6c3dd8f71c0daa535n/aXpertRAT
2021-09-29n/aexe e4b8184869d65a34fb9e0fb43d8b6c252cb153f7139485e3fde6d02cd6898242n/aXpertRAT
2021-09-28n/aexe bb9bfe8005ea5d29b91d9286c81ca934ce6fbc4fa0bcc5c2d404e08441775e2cVirustotal results 19.05%NanoCore
2021-09-24n/aexe 515fbf67c103e796658acaf24ae3762943a56ebf14337ab46bf9e140f61da0f4n/aXpertRAT
2021-09-21n/aexe bc2a5e452669de43c4f4533c995b515bace2941ea5b45bb537085b204ee5d54bVirustotal results 14.71%XpertRAT
2021-09-20n/aexe 85f0af15d708b6a2ea67a30f2a858efc9f32af678a5633289c297f588443cd7aVirustotal results 28.36%XpertRAT