URLhaus Database

You are currently viewing the URLhaus database entry for http://198.23.212.175/golden.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2037369
URL: http://198.23.212.175/golden.exe
URL Status:Offline
Host: 198.23.212.175
Date added:2022-02-08 19:00:05 UTC
Last online:2022-03-12 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-02-08 19:01:14 UTC to abuse{at}colocrossing[dot]com)
Takedown time:1 month, 1 days, 11 hours, 31 minutes Bad (down since 2022-03-12 06:32:35 UTC)
Tags:AgentTesla link exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-03n/aexe 556d815dcd9833355dab3fead60f6d564fe02ce644c6fc9342933faa1c2c0cedn/a 
2022-03-02n/aexe 30cdeafb9f631a61e5fc1812018c1535d3b707aa4b58243ce6e26b177e7bc266n/aAgentTesla
2022-02-22n/aexe 08224f7c58e2e91e18aea6b7ee9611c1de6902ab1ea4c2fc79ce0d5a2b6fbdf5n/a AgentTesla
2022-02-21n/aexe 043fac93fcdb39690d319eef310048b4e2f0e61281685dddb071511760781026n/aAgentTesla
2022-02-08n/aexe 4f4b5ae0f0189074748699df099160023d7b54c5f078d8ae449066bb94479811Virustotal results 27.94%Formbook