URLhaus Database

You are currently viewing the URLhaus database entry for http://172.245.214.91/fridaexploit1.vbs which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2768670
URL: http://172.245.214.91/fridaexploit1.vbs
URL Status:Offline
Host: 172.245.214.91
Date added:2024-02-23 16:37:09 UTC
Last online:2024-02-26 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2024-02-23 16:38:12 UTC to abuse{at}colocrossing[dot]com,net-abuse-global{at}hostpapa[dot]com)
Takedown time:3 days, 1 hours, 24 minutes Bad (down since 2024-02-26 18:02:51 UTC)
Tags:AgentTesla link vbs

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-02-23n/aunknown 2b59477f9d47cf642f8adeed9f8f1e2f313f7db96341900cfac50fe8717c910bn/a 
2024-02-23n/aunknown 13ab4dc9332e2681c9d581b1bbfb86034defbd750d80569483017cef6de7a531n/a 
2024-02-23n/aunknown 8fac26316c54ca4092f7152f897e1efc25e057944de2e98175d8f61c4e79ff4fn/a