URLhaus Database

You are currently viewing the URLhaus database entry for http://198.46.174.139/66077/winiti.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3062476
URL: http://198.46.174.139/66077/winiti.exe
URL Status:Offline
Host: 198.46.174.139
Date added:2024-07-23 06:43:06 UTC
Last online:2024-07-25 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2024-07-23 06:44:07 UTC to abuse{at}colocrossing[dot]com,net-abuse-global{at}hostpapa[dot]com)
Takedown time:1 day, 23 hours, 29 minutes Poor (down since 2024-07-25 06:14:05 UTC)
Tags:AgentTesla link exe Formbook link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-07-24n/aexe 078910e6360ee0588d569bdfb08de83fc36fd67d954577627806c44a0f11e85an/a Formbook
2024-07-23n/aexe 5d73e29724c66578b8d7cbe1288cabc6531ac1c312183d8325a24f399d3695f0Virustotal results 30.14% AgentTesla
2024-07-23n/aexe df3325fba80354987645e107d3166cfe0b97c56818903e42bb938ce6bff6675cVirustotal results 32.39%Formbook
2024-07-23n/aexe 79c33f8a4caad1ef7a4af4ecd6719210ceee458fa1e811b8dc94d9d8d4114a23Virustotal results 36.49%Formbook