URLhaus Database

You are currently viewing the URLhaus database entry for http://89.197.154.116/Journal.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3195187
URL: http://89.197.154.116/Journal.exe
URL Status:Offline
Host: 89.197.154.116
Date added:2024-09-28 07:15:12 UTC
Last online:2025-06-16 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-09-28 07:16:08 UTC to service{at}transworldcom[dot]com)
Takedown time:8 months, 21 days, 3 hours, 23 minutes Bad (down since 2025-06-16 10:39:17 UTC)
Tags:CobaltStrike link Metasploit meterpreter

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-16Journal.exeexe 23d4d1e52bfebc1246f677534e52ca987b7e439c68b3a3896013f7d5d8245549n/a CobaltStrike
2025-05-09Journal.exeexe ef446c52e2a66339856e8884ac00489cf32f689aeccf270d7a9057c7394d1cb4n/a CobaltStrike
2025-05-06Journal.exeexe 919955c80c21cba2f1d1bd43937262aba4fe7599aa8372cfc0e87d7545ab8d24n/a Meterpreter
2025-03-24n/aexe 78b4dee5401cc286e4639cbd46c8299749660c9ab2f7dc59269c0ed0841bab33n/a CobaltStrike
2024-09-30n/aexe e0fad6ad403b01fb99b906403d2abb21ffd1adf78e88477568291bb0cf392debn/a CobaltStrike
2024-09-28n/aexe 37bdec28067c098d357d9ffb8788813b4ff8ebeeb1132f2a6db109e57ead1896Virustotal results 87.67%Metasploit