URLhaus Database

You are currently viewing the URLhaus database entry for http://192.227.173.78/1256/IGCC.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2728607
URL: http://192.227.173.78/1256/IGCC.exe
URL Status:Offline
Host: 192.227.173.78
Date added:2023-11-06 15:53:07 UTC
Last online:2023-11-11 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: James_inthe_box
Abuse complaint sent (?): Yes (2023-11-06 15:54:05 UTC to abuse{at}colocrossing[dot]com)
Takedown time:4 days, 16 hours, 7 minutes Bad (down since 2023-11-11 08:01:29 UTC)
Tags:AgentTesla link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-09n/aexe 2e1d15229a562b11027034a2bba99da62806fa25c5894285fe86e4fec939b4c1n/aAgentTesla
2023-11-08n/aexe 418f1f11c6a87773b914cd6ce16602aadf8848a7141aafa3a3b8fac5dad1d369n/aAgentTesla
2023-11-07n/aexe a867ea159c83eccfffea15659ad67341ebf3b754f169c3eb2ad7a215a693768eVirustotal results 23.53%AgentTesla
2023-11-06n/aexe 47288109ffdc20ef6cc5f098dba87af97203312f952f63cabbb504d97a03ceafVirustotal results 33.33%AgentTesla