URLhaus Database

You are currently viewing the URLhaus database entry for http://87.121.221.212/tonyspecialzx.doc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2676903
URL: http://87.121.221.212/tonyspecialzx.doc
URL Status:Offline
Host: 87.121.221.212
Date added:2023-07-05 06:57:04 UTC
Last online:2023-07-26 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-07-05 06:58:06 UTC to abuse{at}des[dot]capital)
Takedown time:21 days, 0 hours, 27 minutes Bad (down since 2023-07-26 07:25:35 UTC)
Tags:AgentTesla link doc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-07-18n/artf 1709bb50f3d76ef58a47f8b4af7aeff626029e01ab0cbe53936cfe1a79525c54n/aAgentTesla
2023-07-12n/artf 784efe9ef1e0155ca9ecd6b8c040454c8a9bd12faaab454a012bb78b5c84ad10n/aAgentTesla
2023-07-10n/artf 3a675b3c98999d8816eee415eb6e28a21f46548fcb0a9faa600b587cf77a7681n/aAgentTesla
2023-07-05n/artf 8a2565ee16cf761de7b01ee51b25958c9c8b099e00196050b27bb634e53431eeVirustotal results 49.15%AgentTesla