URLhaus Database

You are currently viewing the URLhaus database entry for http://192.3.194.246/invoice.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2229648
URL: http://192.3.194.246/invoice.exe
URL Status:Offline
Host: 192.3.194.246
Date added:2022-06-08 09:25:10 UTC
Last online:2022-11-20 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-06-08 09:26:11 UTC to abuse{at}colocrossing[dot]com)
Takedown time:5 months, 14 days, 18 hours, 12 minutes Bad (down since 2022-11-20 03:39:10 UTC)
Tags:AveMariaRAT link exe NetWire link PureCrypter rat

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-19n/aexe 195d6535f8f97c525e1777cb2635b187bc905d15b2ef429d3e8a7d87c42575f9n/aPureCrypter
2022-11-10n/aexe 3b825210b99a016893d31e4590d385c83c9eb7c9152657d5c0997eb08d741800n/aNetWire
2022-11-10n/aexe d9165fe9df95eeb0aa98fa4dbc4aeb718342ebf2728c5fdd86e37cd207143aa3n/a
2022-11-08n/aexe b0355698b9cac14e82f75a7b8cc8f49cfcf02e559f5122095cb7156eb44a0143n/a NetWire
2022-11-07n/aexe 14bef316e807375c95d89a2d23d9a9af496dac1c91eaa431614f7881089e2abfn/a AveMariaRAT
2022-10-27n/aexe a21c8ef38b35eda08af936729863498ead8f750de997bc2d55ff9da429872e33n/aNetWire
2022-10-13n/aexe 71e65562e00447d697f996d69ffc7798d96cf2b4799f27a298ce710730802428n/aNetWire
2022-08-19n/aexe 012622e521dee6e1c74c6796c92f1b5d31dda65f11e81c095340ca5ec22bdc3en/a NetWire
2022-08-12n/aexe 2abcdb606044f4db592baa3f9c808bf4fcab2146c49d83ba45a4ccbb20bc8354n/aNetWire
2022-08-08n/aexe 3a6ef5a50738a5230ca6c62f187b62b134ca090ba559f65c8a8204d9a66f724dn/a NetWire
2022-07-08n/aexe 7418fd3ec75f43bed921ecf2df4ba922fbd86c2e1e158bf309bbee13d4374125Virustotal results 28.99%NetWire
2022-07-03n/aexe 167b20bea3cf481d6b08785f82ce2f07dca108e925310df2e3c44b8f662509ecn/aNetWire
2022-06-30n/aexe a884e65e38d3545bd60f61ff95f10f87c1c956327d59e6df8ee9d441e19a3316n/a NetWire
2022-06-08n/aexe 1317694579663bb8bfb86f87f2302076848c260ab23ad6b234c25669c36d3cden/a NetWire