URLhaus Database

You are currently viewing the URLhaus database entry for http://103.147.184.98/windows/networksec.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2396683
URL: http://103.147.184.98/windows/networksec.exe
URL Status:Offline
Host: 103.147.184.98
Date added:2022-11-02 11:13:34 UTC
Last online:2022-11-24 17:XX:XX UTC
Threat:Malware download Malware download
Reporter:Anonymous
Abuse complaint sent (?): Yes (2022-11-02 12:18:11 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:22 days, 4 hours, 45 minutes Bad (down since 2022-11-24 17:03:18 UTC)
Tags:AgentTesla link Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-22n/aexe 3ce438b10e417f7dc1367173684c308c59b43acb4b4f49f0bfb2a3e32987c129Virustotal results 34.29%AgentTesla
2022-11-20n/aexe 194832b67aaa283841ac0a8e901eaa8f9f46c15962af65f5b333ebbcf678a44dVirustotal results 36.62%Formbook
2022-11-11n/aexe 40bd6b05cd5a62f1aeb24faec253f720c88a020eaba61b2ce0613e8a83347aben/aFormbook
2022-11-10n/aexe 406a5754d88d0b63b7f062093347cc92f2c8ae2e87f64cc280ea59dd8fca9d2aVirustotal results 36.23%Formbook
2022-11-08n/aexe 943c99ee5eeb1a5e7178e43195f1c40095a6f6ed0ec33e1e3fe69f8f30c7bbb5n/aAgentTesla
2022-11-04n/aexe 714bf12a2ee6357ab5f463fe1a40f46819ec9434c214035060ed6dc96c3fe27bVirustotal results 18.31%AgentTesla
2022-11-02n/aexe 5c7a5703622f230645d9d688aad24c3851546523f892fca996458709cb1ddba9Virustotal results 31.88%AgentTesla