URLhaus Database

You are currently viewing the URLhaus database entry for http://23.94.148.6/GIB.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2661644
URL: http://23.94.148.6/GIB.exe
URL Status:Offline
Host: 23.94.148.6
Date added:2023-06-15 07:46:08 UTC
Last online:2023-06-26 01:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-06-15 07:47:10 UTC to abuse{at}colocrossing[dot]com)
Takedown time:10 days, 18 hours, 10 minutes Bad (down since 2023-06-26 01:57:10 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-22n/aexe 9b64b277877e4f86c3930908d1e37f769845098763384520575141c0b4f4f372Virustotal results 33.80% 
2023-06-19n/aexe 9322aba6565a41f6866f5641f577fc6f7605b131a1ef15d737bb42e029743fa7Virustotal results 23.94%AgentTesla
2023-06-15n/aexe caf42b1f04263f24d4911b5df67dfe700c046af1b1d5e7f299afcd5f698a4db1Virustotal results 21.21%AgentTesla