URLhaus Database

You are currently viewing the URLhaus database entry for http://192.227.158.103/img/newlee.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:427091
URL: http://192.227.158.103/img/newlee.exe
URL Status:Offline
Host: 192.227.158.103
Date added:2020-08-07 09:31:04 UTC
Last online:2020-08-17 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2020-08-07 09:32:04 UTC to abuse{at}colocrossing[dot]com)
Takedown time:9 days, 14 hours, 58 minutes Bad (down since 2020-08-17 00:30:16 UTC)
Tags:AgentTesla link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-10n/aexe 35bf79ba4554f45681dead25d0fa97e02b3f0c8263ef17149cc47b784c7f7abdn/a 
2020-08-07n/aexe dfd87dd98a08682e2f4f9001e698081dba3ef2c2d6b565d7e4c3cd4aae56fc80n/aAgentTesla