URLhaus Database

You are currently viewing the URLhaus database entry for http://111.90.149.244/igfxtsk.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:365293
URL: http://111.90.149.244/igfxtsk.exe
URL Status:Offline
Host: 111.90.149.244
Date added:2020-05-20 12:06:05 UTC
Last online:2020-05-30 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-05-20 12:06:08 UTC to abuse{at}shinjiru[dot]com[dot]my)
Takedown time:9 days, 11 hours, 59 minutes Bad (down since 2020-05-30 00:05:48 UTC)
Tags:AgentTesla link CrimsonRAT link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-05-28n/aexe 3741c26aee2433083a007741ebd6c62bd3bfd6f9d31e3fa8a995b914fd3eb794n/a AgentTesla
2020-05-20n/aexe 8ad2241815c24934b523082e603316065818decfe0d4897d4a6dee84626c5dfaVirustotal results 21.92%CrimsonRAT