URLhaus Database

You are currently viewing the URLhaus database entry for http://87.120.113.91/image.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3378493
URL: http://87.120.113.91/image.exe
URL Status:Offline
Host: 87.120.113.91
Date added:2024-12-27 13:51:06 UTC
Last online:2025-01-12 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2024-12-27 13:52:11 UTC to abuse{at}ekabi[dot]net)
Takedown time:16 days, 8 hours, 46 minutes Bad (down since 2025-01-12 22:39:10 UTC)
Tags:DarkVisionRAT DBatLoader link exe njRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-01-07n/aexe 87bd876ce006ac681bdc03bb01449c6444f93f8ddf147c6af6b8e1275e3949e9Virustotal results 53.52%DarkVisionRAT
2025-01-07n/aexe 80bd5d37d851dc02ff3777786a27575787ff6742839ddbe451403c6939f56a9fVirustotal results 18.06% 
2025-01-06n/aexe 939c125accb6e2f939bc239c45d3ead938a0c0bcd63d77fbde11ed96ed1a1c76Virustotal results 26.76% DBatLoader
2025-01-02n/aexe 155854758b79cdee58f7df5c1a4a07d3b19b3d64a0a58b2e8faf6d8b67042f3cn/anjrat
2025-01-02n/aexe 200566dea238327c1f05f8216f0ae1e991d01e48a6f3fd7cd6c645f911c4da95Virustotal results 47.14% 
2024-12-30n/aexe f96c269716f360aa2fbb1926dda79c3ff47ea7d8ec6615cde06b205d28400f79n/a DarkVisionRAT
2024-12-30n/aexe 887a49ba65548dfe2e4cd6abcf1d106adf2c63c3c6978f55f157597ab90cd235n/a 
2024-12-27n/aexe bbb59f158a76d0b043c7d050bba4c4ad82b94d383f9db265119a24360d7279e4n/a DarkVisionRAT