URLhaus Database

You are currently viewing the URLhaus database entry for http://172.245.27.21/you.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2003275
URL: http://172.245.27.21/you.exe
URL Status:Offline
Host: 172.245.27.21
Date added:2022-01-24 18:25:05 UTC
Last online:2022-01-26 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-01-24 18:26:21 UTC to abuse{at}colocrossing[dot]com)
Takedown time:1 day, 13 hours, 38 minutes Poor (down since 2022-01-26 08:05:10 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-25n/aexe 1825b0aa486178b4a14e4dc3e8ce3f04180ada7aafcfb375e959ac0c1cc66fd1Virustotal results 25.00%AgentTesla
2022-01-25n/aexe 23c38809e80f5f176d8f44eb232184ba707e03f28ef0680d5cec943cb93966f8n/aAgentTesla
2022-01-25n/aexe a6bc8141d94e9cce73fa5227db528b93402cbb9609c509e41b9ddc1008fe5663n/a 
2022-01-24n/aexe 9edfb1d8c25f17d4b5c94398f3eff45d7e8d7d33c94e60c3f358ffdc4fa92627Virustotal results 30.77%AgentTesla