URLhaus Database

You are currently viewing the URLhaus database entry for http://89.197.154.116/Launcher.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3088292
URL: http://89.197.154.116/Launcher.exe
URL Status:Offline
Host: 89.197.154.116
Date added:2024-08-04 12:30:08 UTC
Last online:2025-03-11 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-08-04 12:31:09 UTC to service{at}transworldcom[dot]com)
Takedown time:7 months, 9 days, 2 hours, 52 minutes Bad (down since 2025-03-11 15:23:34 UTC)
Tags:backdoor CobaltStrike link exe Metasploit meterpreter

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-09-26n/aexe f0e112f6c358b2468e1df30c26c00d7cbfff701c0befbb8a291dbc5e8ffb1c37n/a Metasploit
2024-09-24n/aexe b7ec5fda4c56b8aedf7fb93971d3ff9d115804822f8ba9601df4c53757af5502n/aMetasploit
2024-09-13n/aexe cf80605f4611fe7d71a6f3e0bd4014e8fbb412f64bbcf50cdf7456a61ad3babcn/a Meterpreter
2024-09-09n/aexe 7333d9620b2d6517b3c1d3c4abfb28299973478693bb588f07d8da2cdbf59a07n/a Meterpreter
2024-08-30n/aexe 9e43386a1ac03a9a8417f2fcaf68a89c1483719067714ed90995a6df2aa5d018n/a Meterpreter
2024-08-04n/aexe 14f21a1b7991bae07182b22c03f633e54e39a581e4898cb95eb5853e4359c819Virustotal results 74.32%CobaltStrike