URLhaus Database

You are currently viewing the URLhaus database entry for http://91.92.246.47/3tuvq.js which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2735462
URL: http://91.92.246.47/3tuvq.js
URL Status:Offline
Host: 91.92.246.47
Date added:2023-11-27 06:51:06 UTC
Last online:2023-12-04 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-11-27 06:52:05 UTC to abuse{at}limenet[dot]io)
Takedown time:7 days, 14 hours, 57 minutes Bad (down since 2023-12-04 21:49:45 UTC)
Tags:AgentTesla link ascii js

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-12-04n/aunknown adfa25ebfb43642c0e034273bcda5e64ba2e6f143ca113cba0d8d3fdeb1ccf7en/a 
2023-12-01n/aunknown 8b081204158fd05c592b011f00c51be075eeafb4cb92bf2c8f4e773519a27ea4n/a 
2023-11-29n/aunknown f1a6ec983635a0843830fa27c89021a9c7ce8531629bb600521879c196f52b3an/a 
2023-11-27n/aunknown 3b15e80745d77ea0978adab892616ef94a6a28954c50864742a79b10ea2e850an/a 
2023-11-27n/aunknown 5f57cbb48d911fda81730edc42b0c674a7837fd5420662591ae42ae3ad52c35dVirustotal results 11.86%