URLhaus Database

You are currently viewing the URLhaus database entry for http://192.3.141.134/document.doc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:783759
URL: http://192.3.141.134/document.doc
URL Status:Offline
Host: 192.3.141.134
Date added:2020-11-03 18:50:05 UTC
Last online:2020-11-14 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: stoerchl
Abuse complaint sent (?): Yes (2020-11-03 18:52:17 UTC to abuse{at}colocrossing[dot]com)
Takedown time:10 days, 18 hours, 9 minutes Bad (down since 2020-11-14 13:01:54 UTC)
Tags:AgentTesla link RTF

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-11-06n/artf 13ba7d40a2b483bd278a526c6c67f5988e1d53ffdec5398398dad6f0035da174n/aAgentTesla
2020-11-05n/artf 7dbd833f713206e4406e598c140bf3c54d1f73c98b8e516c4fbdb695f7fd717dn/aAgentTesla
2020-11-04n/artf d4117443a89d53c06a34738989637574edbc8ba8befc607b6895f239a65e88bcn/aAgentTesla
2020-11-03n/artf af31e1fc29819a6dc4d6240f856a3465aaff564fc5c2dff5788d5e8419f2e30eVirustotal results 40.00%AgentTesla