URLhaus Database

You are currently viewing the URLhaus database entry for http://23.95.13.131/jesu.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:683978
URL: http://23.95.13.131/jesu.exe
URL Status:Offline
Host: 23.95.13.131
Date added:2020-10-12 09:49:05 UTC
Last online:2020-10-13 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-10-12 09:50:05 UTC to abuse{at}colocrossing[dot]com)
Takedown time:1 day, 1 hours, 15 minutes Poor (down since 2020-10-13 11:06:00 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-12n/aexe f5341d66214d3735ee48fb7344753c6d4d8d9a8c5d0a3fa3d55fa6ceb7fff74en/aAgentTesla
2020-10-12n/aexe 7ed42f7ef1538a1e13b685f37ed0b2995fdd7151af2a5ae97c68112bb244ef8dn/aAgentTesla
2020-10-12n/aexe a58b3b7f178d68f4a4c9a1985bc2add6b951f449d18050a50282ab98d0884a8an/aAgentTesla