URLhaus Database

You are currently viewing the URLhaus database entry for http://2.56.57.124/ori.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2213638
URL: http://2.56.57.124/ori.exe
URL Status:Offline
Host: 2.56.57.124
Date added:2022-05-27 07:06:04 UTC
Last online:2022-06-17 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-05-27 07:07:06 UTC to abuse{at}serverion[dot]com)
Takedown time:21 days, 16 hours, 12 minutes Bad (down since 2022-06-17 23:19:41 UTC)
Tags:32 AgentTesla link exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-12n/aexe 31daf38bc11af2b2a75310c1070c8e23d8a856e3b1a5023317c60176ef302f7en/a RedLineStealer
2022-06-10n/aexe 35c7c059d383f4eb45babef6987429090029162bbbeae347188c851547a6db24Virustotal results 39.71% 
2022-06-02n/aexe c1e9d93f50bf02c2adb4d8da178db35701a8a7ccc8a452740f68933829d6b1dfn/a AgentTesla
2022-05-30n/aexe 7b17b8aa3fc069bf16a6d6bf77b1379361db53ee67af442d4edbebb5e241cf40n/a AgentTesla
2022-05-30n/aexe 709a7672f763737e5490f42cc67e7de9e5c44cb85af34a546cdd4c519370cf2dn/aAgentTesla
2022-05-28n/aexe 03920d7fd96be69ab56cb8d5bb1968419254d064f7ff4630c05ff52f83eb3b36n/aAgentTesla
2022-05-27n/aexe d771c9a2281f020dc96e9d38f050987a4c607790388017b8d1bf560851541e1aVirustotal results 37.88%AgentTesla