URLhaus Database

You are currently viewing the URLhaus database entry for http://45.81.39.123/sogn.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2721924
URL: http://45.81.39.123/sogn.exe
URL Status:Offline
Host: 45.81.39.123
Date added:2023-10-18 07:48:05 UTC
Last online:2023-10-31 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-10-18 07:49:04 UTC to abuse{at}des[dot]capital)
Takedown time:13 days, 12 hours, 25 minutes Bad (down since 2023-10-31 20:15:00 UTC)
Tags:32 AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-10-31n/aexe 5681ddcbe10e98bab3827dc512ab59c2fed4770093e580ebb487b8175746e77fn/a AgentTesla
2023-10-30n/aexe dc5a6c0264dc1bd2b948b6bf82b6912e8d7a8e691f95a2dcac4f7f6f0a5abb1en/aAgentTesla
2023-10-30n/aexe e62db2b3e53b049d2daf287b2b1346803ded2b7686e03e7f54a42825f7f0d139n/a AgentTesla
2023-10-30n/aexe 391b2e4031943c1d1eb402ca700a3c1978f45b994f06bf3e1d0ea70073689406n/a 
2023-10-24n/aexe 604a3dcdc1286e50c884d4f6de4916f146b166f3ef1466d4706f3e6ee0108812n/a AgentTesla
2023-10-24n/aexe b9bf0dc9cb606486b15d845acede348241b80759debfd81b3ce6826f4e8760a3Virustotal results 29.17% AgentTesla
2023-10-23n/aexe 5d1c0f80d075b65a86d2587ad4ecbbcd56605f313a7f9c35ac60af1646186733Virustotal results 26.39% AgentTesla
2023-10-23n/aexe 8b30cfc87fa641f41e4107a8b9eea205499e7d0626d15a9646fcf92b19a9dffan/a AgentTesla
2023-10-20n/aexe 86f2001b53456ca09967483c59b6ff571e1c352a7779a529d9ccefbf10d9f596Virustotal results 20.29% AgentTesla
2023-10-20n/aexe 92648a35b3066283cd6a8f71e57290fd0d8785f28d3fa8fea21deb2c6fcb91e5Virustotal results 25.00% AgentTesla
2023-10-19n/aexe 7f712f9a8adea9db2982c7780c6011df14df81cfb68ee881fc6e046db7dccdb7Virustotal results 26.39% AgentTesla
2023-10-18n/aexe 1f508794b33e17edc44eda815b6e76d7f55083d8225340885554b26c8450c95cVirustotal results 52.78%AgentTesla