URLhaus Database

You are currently viewing the URLhaus database entry for http://107.172.93.10/matt1/kyc1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1636050
URL: http://107.172.93.10/matt1/kyc1.exe
URL Status:Offline
Host: 107.172.93.10
Date added:2021-09-20 15:36:06 UTC
Last online:2021-09-23 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-09-20 15:37:05 UTC to abuse{at}colocrossing[dot]com)
Takedown time:2 days, 18 hours, 22 minutes Poor (down since 2021-09-23 09:59:54 UTC)
Tags:AgentTesla link exe Formbook link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-21n/aexe c2fd119078931fcec24c044573a7ffada54095ef9b8fa76760228c3960bf3e97Virustotal results 17.65%AgentTesla
2021-09-21n/aexe a5ccb1863a186b32287b8cd061207ff95d8c34f7ff8d1749846f35188c15ab0dVirustotal results 20.59%AgentTesla
2021-09-21n/aexe 5ee16ef3270effce196090de88536ab21e4bf6ccc7b16ddd54c68bc44c3045fdn/aFormbook
2021-09-20n/aexe 2519d3c81b62ad689a15a96d31d15c353558f78b4b64af3eff67c93c22a86df6Virustotal results 17.65%Formbook