URLhaus Database

You are currently viewing the URLhaus database entry for http://103.140.251.116/destop/.winlogon.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1646524
URL: http://103.140.251.116/destop/.winlogon.exe
URL Status:Offline
Host: 103.140.251.116
Date added:2021-09-28 09:32:38 UTC
Last online:2021-10-04 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-09-28 09:33:04 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:5 days, 20 hours, 25 minutes Bad (down since 2021-10-04 05:58:07 UTC)
Tags:AgentTesla link exe opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-30n/aexe e44e8b7ce7472d80c6fbd22be5899efd6932d4074a4ad8c4d0a08532fe9edf1dn/aAgentTesla
2021-09-30n/aexe 6461aaeb3fa82c8acccd75bb6b1443e9d59f8ea1c53ef92885f880c8fa2c74c6n/aAgentTesla
2021-09-30n/aexe c9a586790e7846585e2570a9233176c20f05173ca9b716af823fd17a8825f02an/a AgentTesla
2021-09-29n/aexe de754395772ed26856f541dd717fb21799ad503c407fc01f40400e319e68dfc1n/a AgentTesla
2021-09-29n/aexe 2b0433f5696ef9d7b2dfec117200ba52d566837a2fe7faf64c9cdb85a982c91en/aAgentTesla
2021-09-28n/aexe 63d90793ac2e572399270a4bc711722db3140f8e566ee086edee17d19f3bca13Virustotal results 15.94%AgentTesla