URLhaus Database

You are currently viewing the URLhaus database entry for http://20.253.174.196/file2/file2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2508474
URL: http://20.253.174.196/file2/file2.exe
URL Status:Offline
Host: 20.253.174.196
Date added:2023-01-15 14:11:11 UTC
Last online:2023-03-14 01:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-01-15 14:12:05 UTC to abuse{at}microsoft[dot]com)
Takedown time:1 month, 27 days, 11 hours, 3 minutes Bad (down since 2023-03-14 01:15:30 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-01-16n/aexe 72afe114ad4b8fd515e46dd2a26514ad13415ea35dbcf4eb544b96c6abf9fb28n/aAgentTesla
2023-01-15n/aexe be867c634d6f6a4ff7cdc7a845795403edfd78f91b7d0877553f28340641fe58Virustotal results 22.86%AgentTesla
2023-01-15n/aexe fd33cc13da8bded3a01328e150a9625be707fea3ff108119df4effe4ee543053Virustotal results 24.29%AgentTesla