URLhaus Database

You are currently viewing the URLhaus database entry for http://213.209.150.18/agodee2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3548020
URL: http://213.209.150.18/agodee2.exe
URL Status:Offline
Host: 213.209.150.18
Date added:2025-05-20 09:24:09 UTC
Last online:2025-09-15 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-05-20 09:25:09 UTC to abuse{at}virtualine[dot]org)
Takedown time:3 months, 28 days, 5 hours, 25 minutes Bad (down since 2025-09-15 14:50:44 UTC)
Tags:exe MassLogger link SnakeKeylogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-26agodee2.exeexe f72ec4b2bf013defbeda53f2fc69444440cad22960856170c45fbc1e38812f85n/a MassLogger
2025-05-26agodee2.exeexe fc1da2a32fd040ef17062c86275f1fd1d7f97569a8feb4f603530ccecfdc363an/a MassLogger
2025-05-23agodee2.exeexe 1bf2bec8f67855ab9f33fcfd34c94d11ef059eb33395d09c03f7be957c728dc5n/a MassLogger
2025-05-23agodee2.exeexe 1f4f953650c958c52a4cb2dcb0e403bb9d28cee29c60427c25cc991cd0aaf926n/a MassLogger
2025-05-20agodee2.exeexe b4a06f1be6894b9d689ca9a76ec35bde31c5fcd61311955dc3b286575d832dbbVirustotal results 29.17%SnakeKeylogger