URLhaus Database

You are currently viewing the URLhaus database entry for http://147.124.216.113/image.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3386512
URL: http://147.124.216.113/image.exe
URL Status:Offline
Host: 147.124.216.113
Date added:2025-01-02 17:07:09 UTC
Last online:2025-01-14 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: Joker
Abuse complaint sent (?): Yes (2025-01-02 17:08:16 UTC to abuse{at}spinservers[dot]com)
Takedown time:12 days, 0 hours, 14 minutes Bad (down since 2025-01-14 17:23:01 UTC)
Tags:DBatLoader link downloader malware trojan VIPKeylogger

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-01-07n/aexe e5393c34240b7e1b8a35052d7e151c324a4aa6424b5a6e1a45717157042fb9abn/a DBatLoader
2025-01-06n/aexe 03b17e6fe6ce874c0cf78b2e560f5fb4106e07ce33799632b2e1bbf24e9fb371n/aDBatLoader
2025-01-05n/aexe 52f70aceaac84fb1b61e78e36a3f8642875ce6528819060470242fb5312d16e5n/a DBatLoader
2025-01-02n/aexe f65d5f51c5b69891d73c3799b4ed4d53fea665a6ef5b3d0cce8cae1e96c0e785Virustotal results 33.33%VIPKeylogger