URLhaus Database

You are currently viewing the URLhaus database entry for http://198.12.66.102/vsl.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:636154
URL: http://198.12.66.102/vsl.exe
URL Status:Offline
Host: 198.12.66.102
Date added:2020-10-01 17:07:04 UTC
Last online:2020-10-03 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-10-01 17:08:04 UTC to abuse{at}colocrossing[dot]com)
Takedown time:1 day, 23 hours, 43 minutes Poor (down since 2020-10-03 16:51:27 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-02n/aexe 0a9e76d04b5ad405d59b6092f545f48dac62b1ce8ed10a260e4f90edff474c24n/aAgentTesla
2020-10-02n/aexe 586f2a10cc5842868b0e44f88871f55d3ea0cee6a882589df7d2bfd6fa9adb07n/aAgentTesla
2020-10-02n/aexe f7fc558a477c78eb451cf6479b13d26058bffee1761996c85048182f9596f498n/a
2020-10-01n/aexe 58e919965df896c5650448556e2a6d96ecc92a8f2af4dbdf81f4a86c2df5a091Virustotal results 8.45%AgentTesla