URLhaus Database

You are currently viewing the URLhaus database entry for http://103.141.138.247/off/OFF.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:402267
URL: http://103.141.138.247/off/OFF.exe
URL Status:Offline
Host: 103.141.138.247
Date added:2020-06-26 07:16:08 UTC
Last online:2020-07-22 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-06-26 07:18:02 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:25 days, 18 hours, 56 minutes Bad (down since 2020-07-22 02:14:49 UTC)
Tags:AgentTesla link exe opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-14n/aexe cf6bc45a0a0680ae2e9ea3de3202334f030715210969ffb776783f8c114a0ffbn/a AgentTesla
2020-07-13n/aexe be8e472cbf953529be97d126d5fafebe1ad6dc69a8279258307b4a24770e131dn/aAgentTesla
2020-07-10n/aexe 93c3465ce15fd99b3fa195b462ec72e1836589fe53f6a8f114bf8a2a277b1f69n/a AgentTesla
2020-07-08n/aexe 956c868efedeb3555f860976e09e624cb15ceb7d02106d9451333d59336c2481n/a AgentTesla
2020-07-08n/aexe 1cf13c02d86a00267227f00ebd9e88cf6d64a7d8167e51e74d1798bde4c414fcn/a 
2020-07-06n/aexe 0174855748327565798fbf78c2b4b306257c1bd4ec7eeb6b62922d0561191377n/aAgentTesla
2020-07-02n/aexe fcecd5bf9fc31bfd7f38010364f41b4f0dc6c871d8f4eec2ad17257850d33e1an/a AgentTesla
2020-07-02n/aexe fcecd5bf9fc31bfd7f38010364f41b4f0dc6c871d8f4eec2ad17257850d33e1an/a AgentTesla
2020-06-26n/aexe 35b9275ade5e52626dae3906b328adcb9d7faad0450d36100a99e0baa80a675fn/a AgentTesla
2020-06-26n/aexe dcb2c9ba962e3164eb3fefe869229ee5eb1f1971f4a2b3a7a5f1cc054420f0d2n/a AgentTesla
2020-06-26n/aexe 0474f95668bc717bc90f9f4a92914cf7d28b96118edbeb2b3b64ecb692f19695n/aAgentTesla