URLhaus Database

You are currently viewing the URLhaus database entry for http://171.22.28.208/download/rise/StealerClient_Sharp.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2711514
URL: http://171.22.28.208/download/rise/StealerClient_Sharp.exe
URL Status:Offline
Host: 171.22.28.208
Date added:2023-09-13 14:35:15 UTC
Last online:2023-09-27 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-09-13 14:36:05 UTC to matrixllp{at}skiff[dot]com)
Takedown time:14 days, 1 hours, 46 minutes Bad (down since 2023-09-27 16:22:54 UTC)
Tags:32 AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-09-21n/aexe 92462821c6baea822ee3335568750b1707eab65245b55e19f4b2456d9f3dc0d2n/a AgentTesla
2023-09-19n/aexe ecf7bd140e00924b0bef6190eac4c42c36e670723eb38eb26cfff1b4b4366d65n/a 
2023-09-13n/aexe d284fdf1f86180afb01b47ac07faa898ecffc585f3fe2dfc27225f1a1f12354eVirustotal results 62.86%