URLhaus Database

You are currently viewing the URLhaus database entry for http://210.125.101.75/agent.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3356783
URL: http://210.125.101.75/agent.exe
URL Status:flame Online (spreading malware for 1 year, 5 month, 15 days, 7 hours, 58 minutes)
Host: 210.125.101.75
Date added:2024-12-18 16:21:06 UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-12-18 16:22:12 UTC to irt{at}nic[dot]or[dot]kr)
Tags:Metasploit meterpreter

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-22agent.exeexe a9709a59c71d5036551a82122141d978c198781a5ed8f26bb3f2a67d56364b9an/a 
2025-04-22agent.exeexe ca3edfbbcfeba2a7f6c363487bf673e1cbcdc24e849c8b339f7ec27470f084f9n/a 
2025-04-22agent.exeexe ccbc7c8f8edc0a74d7457aa8366625fcd3026b81dadbc4106156ea7310a00382n/a 
2024-12-18n/aexe c2e367c6f38b6276680526550403573a74e4db2f2469c7936afc2b935781feb6Virustotal results 90.14% Meterpreter