URLhaus Database

You are currently viewing the URLhaus database entry for http://79.110.48.52/kwen.vbs which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2715890
URL: http://79.110.48.52/kwen.vbs
URL Status:Offline
Host: 79.110.48.52
Date added:2023-10-02 17:46:06 UTC
Last online:2023-10-16 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-10-02 17:47:04 UTC to abuse{at}rocketdedi[dot]com)
Takedown time:13 days, 19 hours, 8 minutes Bad (down since 2023-10-16 12:55:22 UTC)
Tags:AgentTesla link vbs

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-10-13n/aunknown 9f4b7fe124d2d25e873d33a6611c1fa84d45e98b9670af3ba65d93b6c1f6dbe1n/a 
2023-10-09n/aunknown 4a549500046baad72152ec11819dab9f26510b9fe9fb7290e561d6f79864954fn/a 
2023-10-04n/aunknown 58d0fbfe076e002c31922e0f296eee47319dfc44c38a507b2fa49e252047c25en/a 
2023-10-02n/aunknown e611dc4582f0eae7284d4f6800d95d5f4d1604b4cc79e0f0a15a07c2578c71ean/a