URLhaus Database

You are currently viewing the URLhaus database entry for http://23.146.240.230/stub.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:413096
URL: http://23.146.240.230/stub.exe
URL Status:Offline
Host: 23.146.240.230
Date added:2020-07-15 10:06:04 UTC
Last online:2020-07-16 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: theDark3d
Abuse complaint sent (?): Yes (2020-07-15 10:08:03 UTC to noc{at}vdinetwork[dot]com)
Takedown time:1 day, 4 hours, 47 minutes Poor (down since 2020-07-16 14:55:43 UTC)
Tags:AgentTesla link NanoCore link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-16n/aexe d177132fa7941febe11431bb8dd897e86464eaac755b8e693ceba29be0f90afan/aNanoCore
2020-07-16n/aexe 63a5298bea16570eec0d85b42c13f422cb22052429130150a9ff3acac695bf1dn/a AgentTesla
2020-07-15n/aexe 09cf9e7b4f32df0516fd394b6cf91e25951633d6ea74140df6697577111889abn/aNanoCore
2020-07-15n/aexe baf5098a21b4d571d2c23727229db27ee1c81216aeddbe59ee391f94154ca33dVirustotal results 35.21%NanoCore