URLhaus Database

You are currently viewing the URLhaus database entry for http://192.210.214.146/file.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:807263
URL: http://192.210.214.146/file.exe
URL Status:Offline
Host: 192.210.214.146
Date added:2020-11-11 13:09:15 UTC
Last online:2020-11-25 15:XX:XX UTC
Threat:Malware download Malware download
Reporter:Anonymous
Abuse complaint sent (?): Yes (2020-11-11 13:10:03 UTC to abuse{at}colocrossing[dot]com)
Takedown time:14 days, 2 hours, 27 minutes Bad (down since 2020-11-25 15:37:40 UTC)
Tags:AgentTesla link Formbook link Loki link QuasarRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-11-19n/aexe be97e48f58000a3482ffd6b332e60b08a38ff72eb132fadc44d2d72de371e74fn/aAgentTesla
2020-11-19n/aexe edc80c67f18684f69dade8ffe6f190ca30eb0857ad5bb6a184ac76ac3cd1dde4n/aLoki
2020-11-17n/aexe 961b36bb78d27b3432fae08e5c4272fe295b5e24e832c6f6bf1ec3cf87057dabVirustotal results 1.43%
2020-11-17n/aexe ab8e71a8035999799c88b25d8bd33d1ab5ca07075320e50f30cba174c7b82b4aVirustotal results 48.57%QuasarRAT
2020-11-17n/aexe 8b211eb288370426bec2c6472ccb0830a9487e3c0c53fcbf9061c4349bd1e2c8n/aLoki
2020-11-16n/aexe 24f9deac942621a63882293c9e365f068ecf4e1bb78485a2dce42765eb5e37b5n/aLoki
2020-11-16n/aexe 58bb593d1ee92aaa48bec847b56d18b04e1d140f4ab13e7c4f4b25a597aed4d9n/aAgentTesla
2020-11-16n/aexe e8fc1668976751ae8b6a453020ed96065aa48636120b852363c45dfd26ec34d8n/aAgentTesla
2020-11-13n/aexe 6479d5e485285c17d7bfae921700f9562405796a71938e50f131b7801d93c0c7n/a Loki
2020-11-13n/aexe 1da6b95adbed36dc2ac3abcc35f4a5572c2a5a1f2ca5d9f7ff9363537b8f4ff3n/a Formbook
2020-11-12n/aexe f840cba1b1f238e8f231fefa32b6b95e1d11af140075db304afbd3cbff6ec988n/aLoki
2020-11-12n/aexe 47cd254d9e0104e8fbe51d35b06c2e250c8af9d6896702f88c793eaeda58bd18n/aLoki
2020-11-12n/aexe 24098778dca36a5ff9aa4ce38ab0bd9cdecfd3a8dc3f563e694111003d6f7827n/aAgentTesla
2020-11-11n/aexe a148266deff592c1ba38bc1616f5483f7ba9d73f97dd88a3def54834b8434a1eVirustotal results 24.29%AgentTesla