URLhaus Database

You are currently viewing the URLhaus database entry for http://91.212.150.176/fulla.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1067735
URL: http://91.212.150.176/fulla.exe
URL Status:Offline
Host: 91.212.150.176
Date added:2021-03-15 00:30:08 UTC
Last online:2021-03-17 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-03-15 00:31:02 UTC to alexx[dot]person{at}gmail[dot]com)
Takedown time:2 days, 11 hours, 31 minutes Poor (down since 2021-03-17 12:02:51 UTC)
Tags:exe ServHelper link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-03-15n/aexe d53c9d7349bdbee8f73709c263cb08c2ca721365bb0670993b81fe2fd9200bacn/aServHelper
2021-03-15n/aexe 75f15682957ba6b77048878682164cb29e43cea0b92c34b5491d3b9277e6776en/a ServHelper
2021-03-15n/aexe e0b92aab41d80eae8988509f4fce97bd06ac191f00a2adaeeaceaabc2581301cn/a
2021-03-15n/aexe a27fa7724da938df040a3e535f2be9cec4d6d93bd4f2e5ec2ba79560f84cb69cVirustotal results 44.93%ServHelper