URLhaus Database

You are currently viewing the URLhaus database entry for http://91.212.150.244/al.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1559087
URL: http://91.212.150.244/al.exe
URL Status:Offline
Host: 91.212.150.244
Date added:2021-08-24 04:58:05 UTC
Last online:2021-08-26 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-08-24 04:59:02 UTC to alexx[dot]person{at}gmail[dot]com)
Takedown time:2 days, 14 hours, 59 minutes Poor (down since 2021-08-26 19:58:30 UTC)
Tags:ServHelper link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-08-26n/aexe 14a1f66ffe45491f19703775244eca0c03a342a10ca3ecb205247fb63dbab608n/a 
2021-08-25n/aexe a600f541bdf44bbe1418186c9456b7274843764a8255ae0b5cb321cb77227dd3n/a 
2021-08-25n/aexe 2063e7cc6524afed5360052106f2ba59135244ab21676b533d16c3eb5767590en/a
2021-08-25n/aexe 9b1c4918d748cd7cf689dfea9e821b23f215d09ebaf3f62eb978e3290967eeaan/a 
2021-08-25n/aexe ec629452eefffad0dd94360eaba8f256bc7a6cc83ad2f9d605f3cb2104ca0d3an/a 
2021-08-25n/aexe 82984b1140d6296e663129295ef7cbf79fd5c56a3422f9ab4693d836c35ec564n/a 
2021-08-24n/aexe 062f99e70dc7dd174444d7fd350f504927947645b9bded138effc436bd83d185n/a 
2021-08-24n/aexe 770d0ee03685c3091c290a51a9bfdb805661fb7f8d2ec45c41aeaa2be43e9730n/a 
2021-08-24n/aexe 1f3c161f8369a583d1e970a7b2db1c1b5e3b018266e4f47ca0cd7e9b9d9f95b1n/a 
2021-08-24n/aexe a8f40382ead50449d872ddb8db0251148747fb63fed23bf4647d14fd226a2fc2n/a
2021-08-24n/aexe 02031c62d916cdd41d26a271e93ec5b06eabfa910187207b02ead07fd480c2a9Virustotal results 58.82%ServHelper