URLhaus Database

You are currently viewing the URLhaus database entry for http://ateliermue.info/wp-content/aa.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1685447
URL: http://ateliermue.info/wp-content/aa.exe
URL Status:Offline
Host: ateliermue.info
Date added:2021-10-16 16:14:13 UTC
Last online:2021-10-25 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-10-16 16:15:03 UTC to hostmaster{at}nic[dot]ad[dot]jp)
Takedown time:8 days, 16 hours, 29 minutes Bad (down since 2021-10-25 08:44:14 UTC)
Tags:32 AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-24n/aexe f4b03241b05ab574499decb9f59ceabc87509849569c614df462a2fa92c6f4adVirustotal results 39.39%AgentTesla
2021-10-19n/aexe 4ed0b0474741e959230eb8a17efbc5e0db94fba7f46499596dd6359b4cf16637n/aAgentTesla
2021-10-18n/aexe 0ba7fc9dbbaac148179236aedbb5193eba1506769f139c0fba91c2d211c0c7b0n/a AgentTesla
2021-10-18n/aexe 2abf2a8978d75c05076b1b55593d4c619ff6fcb92146340d72f76aa9e8bed47cVirustotal results 19.70%AgentTesla
2021-10-17n/aexe 6e1687a0483bcec04366a9d825c96f255b3a3417852c08f1d7a3f58bff3ac8bfn/a AgentTesla
2021-10-16n/aexe 13997ca8537609439505135fd73fbc53cd410fc54f307b8050c84b0c85bcc920Virustotal results 50.00%AgentTesla