URLhaus Database

You are currently viewing the URLhaus database entry for http://87.121.221.212/gvailantzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2676483
URL: http://87.121.221.212/gvailantzx.exe
URL Status:Offline
Host: 87.121.221.212
Date added:2023-07-04 13:58:04 UTC
Last online:2023-07-26 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-07-04 13:59:07 UTC to abuse{at}des[dot]capital)
Takedown time:21 days, 17 hours, 35 minutes Bad (down since 2023-07-26 07:34:57 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-07-21n/aexe 613e8b04d64b072a61af7b1a5199b74dcc3b5a7ac5a98823c7b2d5ec23cbfbe9n/a AgentTesla
2023-07-21n/aexe 37d3f785f7e11bcd8a237f4180285850effce87097fd4c662a93e4a9a29f1d6bn/a AgentTesla
2023-07-20n/aexe 830b93cdc24c1d75ee7ba0afcaddb58690f9d3ff96ded60ea5657768b188d301Virustotal results 25.35%AgentTesla
2023-07-20n/aexe 0d03f0e57bfc9a9b4e583404b127ae9adff260762252e77d11c95bc6181188ceVirustotal results 28.17%AgentTesla
2023-07-04n/aexe d385b93c9c93907ce2a86d7bd3a882b2f678cb524235b5fd06ca7b9e523adc70n/aAgentTesla