URLhaus Database

You are currently viewing the URLhaus database entry for http://80.76.51.248/kwen.vbs which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2703338
URL: http://80.76.51.248/kwen.vbs
URL Status:Offline
Host: 80.76.51.248
Date added:2023-08-09 16:34:04 UTC
Last online:2023-10-13 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-08-09 16:35:12 UTC to abuse{at}des[dot]capital,abuse{at}serverion[dot]com)
Takedown time:2 months, 5 days, 6 hours, 31 minutes Bad (down since 2023-10-13 23:07:09 UTC)
Tags:AgentTesla link ascii vbs

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-08-28n/aunknown cbb7ee318140eae82740d2496fd405d697f2dadac32ce8b531040efc212e2e4fn/a 
2023-08-23n/aunknown 5c94130c88c24827cdaaed4aa4bee0457dcda78bdda48a96aa6b8d562887e350n/a 
2023-08-21n/aunknown ff3893b0b1dd19b8487d8a2484655e4e069e29b34996439ebe0dbbdc729233dbn/a 
2023-08-16n/aunknown 4761e5c1932d9b3db4dfb8c991ceabd7b775bcee0aeab62ccb9da5b8af5f60d5n/a 
2023-08-14n/aunknown a204250111ee439c53a06c9c1670b736a2e1a9e1e91d7d28c62e1e1a9d0b1456n/a 
2023-08-09n/aunknown a334c6122bad0425124968bc3a443bf3a4ef2aabb1e865f03fee17122f0c6885Virustotal results 13.56%AgentTesla