URLhaus Database

You are currently viewing the URLhaus database entry for http://213.209.150.18/agodee.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3548019
URL: http://213.209.150.18/agodee.exe
URL Status:Offline
Host: 213.209.150.18
Date added:2025-05-20 09:24:09 UTC
Last online:2025-09-15 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-05-20 09:25:09 UTC to abuse{at}virtualine[dot]org)
Takedown time:3 months, 28 days, 6 hours, 2 minutes Bad (down since 2025-09-15 15:27:38 UTC)
Tags:exe MassLogger link SnakeKeylogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-26agodee.exeexe e212600879f4181f4fd3755840f353841050b5e834811b92ccbbd4ba001bed88n/a MassLogger
2025-05-23agodee.exeexe 1bf2bec8f67855ab9f33fcfd34c94d11ef059eb33395d09c03f7be957c728dc5Virustotal results 44.44% MassLogger
2025-05-23agodee.exeexe fea74534ca1dce9ea99fcce1de1068dbbe0d25b76b2f2ee529cdb0522db26d82n/a SnakeKeylogger
2025-05-23agodee.exeexe fea74534ca1dce9ea99fcce1de1068dbbe0d25b76b2f2ee529cdb0522db26d82n/a SnakeKeylogger
2025-05-20agodee.exeexe b4a06f1be6894b9d689ca9a76ec35bde31c5fcd61311955dc3b286575d832dbbVirustotal results 29.17%SnakeKeylogger