URLhaus Database

You are currently viewing the URLhaus database entry for http://176.65.144.3/dev/believe.ps1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3477165
URL: http://176.65.144.3/dev/believe.ps1
URL Status:Offline
Host: 176.65.144.3
Date added:2025-03-14 18:48:06 UTC
Last online:2025-03-24 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-03-14 18:49:09 UTC to abuse{at}dolphinhost[dot]net)
Takedown time:9 days, 14 hours, 22 minutes Bad (down since 2025-03-24 09:11:46 UTC)
Tags:AgentTesla link SnakeKeylogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-19n/atxt 97e9ba7074888218150917c00c8d79d29eaf8c686227a0cacc22219f5b69db48n/aAgentTesla
2025-03-18n/atxt 0ac1d4e752568e257e9c6534948b7695480a6f3f618f70e1651e7dbce762cb9cn/a 
2025-03-17n/atxt 6a11c9a2333c0a9678fd834bab426dec80d6bdbef2ec3ff51c248b5901be61d0n/a 
2025-03-17n/atxt 74e0df02a96648c5f6393912f769e5bb14cd20e4e55852e0393360a5bc90ae8cn/a 
2025-03-14n/atxt f7325182772f91e4293f2751dedef7930430cb91e357f2d643d2dc615816b335Virustotal results 29.03%SnakeKeylogger