URLhaus Database

You are currently viewing the URLhaus database entry for http://194.180.49.147/Nexcdpoed.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2511643
URL: http://194.180.49.147/Nexcdpoed.exe
URL Status:Offline
Host: 194.180.49.147
Date added:2023-01-18 20:03:07 UTC
Last online:2023-01-23 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-01-18 20:04:06 UTC to abuse{at}des[dot]capital,abuse{at}serverion[dot]com)
Takedown time:4 days, 13 hours, 19 minutes Bad (down since 2023-01-23 09:23:42 UTC)
Tags:AgentTesla link exe SnakeKeylogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-01-20n/aexe ba846910ae2ae36a36f62eeaac3d693228dbe07d32484d23795414d5ac5908ffn/aAgentTesla
2023-01-19n/aexe 22566cd4a19b98bd6a300628f8a1ab844fe0898644dc578203cdf34868cc446bn/aAgentTesla
2023-01-18n/aexe a3471688bb87789c9aaed8dd12e2a79356c46eea6b181786adcab310a75787f8Virustotal results 39.44%SnakeKeylogger