URLhaus Database

You are currently viewing the URLhaus database entry for http://185.28.39.18:7777/185.28.39.18/meccazx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2712291
URL: http://185.28.39.18:7777/185.28.39.18/meccazx.exe
URL Status:Offline
Host: 185.28.39.18
Date added:2023-09-18 08:56:07 UTC
Last online:2023-10-28 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-09-18 08:57:06 UTC to abuse{at}des[dot]capital)
Takedown time:1 month, 10 days, 13 hours, 39 minutes Bad (down since 2023-10-28 22:36:40 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-09-20n/aexe 6c5005831dda2266a3f6ae7cacfc7f330650d559eab346496455efb1482a4873Virustotal results 29.58% AgentTesla
2023-09-19n/aexe feba0b216fadce725e92cd532916b43475b2cbda61aa6b7619f56fba2940390bVirustotal results 29.58% AgentTesla
2023-09-18n/aexe e215e9e90f3aa064ca0df91993ab91f086fe918e72c05de21307b75b1cd164ecVirustotal results 25.35%AgentTesla
2023-09-18n/aexe 099239f804cec77a75d9142dbc302c3c75fb607ec967d9ee38ea1eb21b392a49n/aAgentTesla