URLhaus Database

You are currently viewing the URLhaus database entry for http://2.58.149.2/trans.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2229603
URL: http://2.58.149.2/trans.exe
URL Status:Offline
Host: 2.58.149.2
Date added:2022-06-08 09:04:04 UTC
Last online:2022-06-10 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-06-08 09:05:07 UTC to abuse{at}serverion[dot]com)
Takedown time:2 days, 14 hours, 52 minutes Poor (down since 2022-06-10 23:57:53 UTC)
Tags:AgentTesla link AveMariaRAT link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-10n/aexe 3f15e407b8234ab251c158249badba9314196f65e40f49b0bd48f46c04c78955n/a AgentTesla
2022-06-10n/aexe 4b350d60564405dc0b1bcbe7b53b15688d6ff2bff03846f4aa5bc9b9c7de67e5n/a 
2022-06-10n/aexe 12fd9af35210339752f15a0f68e725cd30f9879e1764b43e7bc466c824f8b77dn/a 
2022-06-09n/aexe 9333619417da67f48057fac9c739d78a5e9c523fa7961661ce87d9a293a938c9n/a 
2022-06-09n/aexe dd4f8b37f22b593fa5703d0760eebbc1316e13edf3edabf7e9ade0de7075fd63n/a AgentTesla
2022-06-09n/aexe 922e73490e896a581831e49e8fc5f473ce0cdf0273f8b7cf1db1fb6bb178c1aan/a AgentTesla
2022-06-08n/aexe 7a39b96dfbfc447fc654bd214ec01f93d95e190308aaafd3d821e8afcd670846n/a AgentTesla
2022-06-08n/aexe 1313cca58fdf2c3ce14ce98378ac7066eec82c17232c81a6d13bb08133e1a8efVirustotal results 22.06%AgentTesla
2022-06-08n/aexe a9bdc46a68ce46ea1dbdecb4637931f02bfdb07c2562f7530ba2b43aa1983a9an/a AveMariaRAT
2022-06-08n/aexe 4a6fd916d6b46a2edddcb8b0a9c47bc81726548a88b507866f34e121dcc6bc66Virustotal results 36.76%AgentTesla