URLhaus Database

You are currently viewing the URLhaus database entry for http://89.197.154.116/Extension.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3101638
URL: http://89.197.154.116/Extension.exe
URL Status:Offline
Host: 89.197.154.116
Date added:2024-08-11 14:08:05 UTC
Last online:2025-03-11 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2024-08-11 14:09:07 UTC to service{at}transworldcom[dot]com)
Takedown time:7 months, 2 days, 1 hours, 4 minutes Bad (down since 2025-03-11 15:13:47 UTC)
Tags:Cobalt strike link CobaltStrike link exe Metasploit opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-09-30n/aexe cd1e87caf4e180dc9f1a2f56bab3cb2483e5557c94723bc86bdf6f079472ef20n/a Metasploit
2024-09-19n/aexe b151876e8b4405344dcbf1c7738be9f93f2cf2cc0cde9ba18d73fa443f460ecdn/aCobalt Strike
2024-09-11n/aexe afccc65c8eea945df3889573ce48f81125c26f2255febf2f23f0e4b3461ebd04n/a Metasploit
2024-09-04n/aexe 5374d3d072c93828f4d1a0feaa8ce21e3c3c005849bdc2d1d92da3123b09a68fn/a Metasploit
2024-09-02n/aexe 5fa98c2dcd0db6183e1185c1da37082b5a7a768b10338cadf822fd1b67d92a64Virustotal results 85.33% CobaltStrike
2024-08-22n/aexe 09b386ac68a458be60227cbbb6f66361b303af77cda5059265e0d9ae65bb39ban/aMetasploit
2024-08-21n/aexe 4e65578760c631c3550454b762c7dfa26d21aad368bed1c7cb62301a920070b8n/a Metasploit
2024-08-11n/aexe 3c7765451ee006387b6367e75c7a53c2b4e2ad5639ae27ef80755b11a4123facVirustotal results 87.32% Metasploit