URLhaus Database

You are currently viewing the URLhaus database entry for http://89.197.154.116/Icon.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3195171
URL: http://89.197.154.116/Icon.exe
URL Status:Offline
Host: 89.197.154.116
Date added:2024-09-28 07:15:10 UTC
Last online:2025-06-16 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-09-28 07:16:08 UTC to service{at}transworldcom[dot]com)
Takedown time:8 months, 21 days, 3 hours, 2 minutes Bad (down since 2025-06-16 10:19:03 UTC)
Tags:Metasploit meterpreter

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-23Icon.exeexe a52506eac6e6cd98c6b19c6bce1c4571b500760783b822c15858be48a3d23b34n/aMetasploit
2025-04-23Icon.exeexe 08354f63b796d2f7aeb2655f9ae6d8f9bee7423ad26742e3914c8200fc5db411Virustotal results 73.24% Metasploit
2024-09-28n/aexe 1a2477e7a05ced92b8897b05b5343996364c64ddfec87c5aa4231b6ff9d7218cVirustotal results 91.78%Meterpreter