URLhaus Database

You are currently viewing the URLhaus database entry for http://192.3.216.141/Ywtencv.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3496975
URL: http://192.3.216.141/Ywtencv.exe
URL Status:Offline
Host: 192.3.216.141
Date added:2025-03-31 17:51:51 UTC
Last online:2025-04-22 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-03-31 17:52:07 UTC to abuse{at}colocrossing[dot]com,net-abuse-global{at}hostpapa[dot]com)
Takedown time:21 days, 15 hours, 47 minutes Bad (down since 2025-04-22 09:39:59 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-12Ywtencv.exeexe 08c21a13527015018cae9c7b8872357826cfc2a5239c7c6e81415f258da011a0n/a 
2025-04-09Ywtencv.exeexe 46a300e18dfd012fce503d38dcc5a3b9ffe4fb7e5feb4af9ad9a594e1281a9dan/aAgentTesla
2025-04-07Ywtencv.exeexe 2533fa8f8af39bb703b2efd1f11c016a7d16697d1d1a408b5696c2fae2b399c7n/a 
2025-04-06Ywtencv.exeexe 841c3239e78b2e0ffab3a1648cfc1df9802e3abdffd96ec1b5fd0390050bae20n/a 
2025-04-05Ywtencv.exeexe 15832f3d91b4536e9c7f4dbcbfadc6ec889c0719a804fc4ba3feac9c8d0d2cbdn/a AgentTesla
2025-04-03n/aexe 0375062325e6c00b7975e16b0c6c97e03b5f3c517f312759c6611c4af1ac3164n/a 
2025-04-02n/aexe f41420a653d66879f67ef42066d5bc28ffb885a09db6049ee7764c65594802b6n/a 
2025-03-31n/aexe ac84f3aa1f2de1773ada934125d633c41fa44c01a7d2b0ec703cdf9f74791dfeVirustotal results 38.03%