URLhaus Database

You are currently viewing the URLhaus database entry for http://89.197.154.116/Documents.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3101655
URL: http://89.197.154.116/Documents.exe
URL Status:Offline
Host: 89.197.154.116
Date added:2024-08-11 14:08:10 UTC
Last online:2025-06-16 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2024-08-11 14:09:07 UTC to service{at}transworldcom[dot]com)
Takedown time:10 months, 8 days, 20 hours, 26 minutes Bad (down since 2025-06-16 10:35:50 UTC)
Tags:CobaltStrike link exe Metasploit meterpreter opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-22Documents.exeexe 1b5ba754d148f8784be1ab94b3fb7f3f0ee8a27f18851b8f9c51366037be88den/a CobaltStrike
2024-09-24n/aexe 77550cc0d9aa70e6d6b180538390e67d6acf8eb0802a6381bd14562b90a31ac1n/aMetasploit
2024-08-27n/aexe 763befb50d645b4adea19eed7fd9fde283b888665ff7ac83d78264d7c7db80f5n/a Meterpreter
2024-08-20n/aexe b1bbf3464d0f4b2461c7d56bbfc181091440e2e49588188e314ef2522e4f8c3dVirustotal results 85.14% 
2024-08-12n/aexe ec76d4d641e6bcfea1c76a81727fe9c525121d782346ee3ec88d87de69f45eaeVirustotal results 85.33% Meterpreter
2024-08-11n/aexe a293363f938ff1a68646a7c6d3df548ad000a3ccf326b0b5758039188250bc81n/a Meterpreter