URLhaus Database

You are currently viewing the URLhaus database entry for http://103.144.240.13/1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3153417
URL: http://103.144.240.13/1.exe
URL Status:Offline
Host: 103.144.240.13
Date added:2024-09-02 17:23:10 UTC
Last online:2024-10-24 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2024-09-02 17:24:07 UTC to suliangliang{at}idc021[dot]com)
Takedown time:1 month, 21 days, 19 hours, 30 minutes Bad (down since 2024-10-24 12:54:48 UTC)
Tags:exe farfli Gh0stRAT nitol link PurpleFox ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-121.exeexe 63a74faeb9f157eef07d7bc5372e8e21b1bb53bdba4991d699e1f09ac32a4898n/a Nitol
2024-09-231.exeexe 9740fb71580a1e6809c694ebd1aa132e76d0dc985dbc0721ae6590f3bf5ed19bn/aGh0stRAT
2024-09-071.exeexe 30e1cca4815d2b55fde219f4e30bd1a64a6399934a18d46e60f13cafa2ff0da7n/a 
2024-09-021.exeexe f17af5296ff826f4199381574dccb3dcb8a5deeb811e40929f95c722ab70aeb7Virustotal results 72.00% Gh0stRAT