URLhaus Database

You are currently viewing the URLhaus database entry for http://111.90.149.244/svc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:365270
URL: http://111.90.149.244/svc.exe
URL Status:Offline
Host: 111.90.149.244
Date added:2020-05-20 10:49:10 UTC
Last online:2020-05-26 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-05-20 10:50:07 UTC to abuse{at}shinjiru[dot]com[dot]my)
Takedown time:5 days, 23 hours, 17 minutes Bad (down since 2020-05-26 10:07:40 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-05-21n/aexe c87a719713c51891fa7b0def4b093441934d9f60ef8bd52951e2efb9a030f59cn/aAgentTesla
2020-05-20n/aexe a7fca53f934c51402b4e970ca3895b1de0d44c03276c5838c2db12c7d92a6449n/a
2020-05-20n/aexe 98e1a2634bdb08683bdeecd74dc8511ec54048e83f77f12d69cf83dc48064e52Virustotal results 27.54%