URLhaus Database

You are currently viewing the URLhaus database entry for http://194.180.49.147/Mqbcgo.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2512928
URL: http://194.180.49.147/Mqbcgo.exe
URL Status:Offline
Host: 194.180.49.147
Date added:2023-01-20 01:28:04 UTC
Last online:2023-01-24 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-01-20 01:29:06 UTC to abuse{at}des[dot]capital,abuse{at}serverion[dot]com)
Takedown time:4 days, 18 hours, 37 minutes Bad (down since 2023-01-24 20:06:50 UTC)
Tags:32 AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-01-23n/aexe 5c694c48dab66d0357208d71a8e0cd8ccf57b996fb675aa1b4647d5ff6784183n/aAgentTesla
2023-01-20n/aexe d43404f5a19ca01c3b41b92000336716cdf877822771586d92b6ab348431efe8n/aAgentTesla
2023-01-20n/aexe 372e830ca920a5f2b66e8980e5b9ddedd9343a5c23c6fb48adfc762568eacb51Virustotal results 40.85%AgentTesla