URLhaus Database

You are currently viewing the URLhaus database entry for http://154.209.248.56/46.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1725884
URL: http://154.209.248.56/46.exe
URL Status:Offline
Host: 154.209.248.56
Date added:2021-10-29 08:35:06 UTC
Last online:2021-11-08 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-10-29 08:36:05 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:10 days, 8 hours, 30 minutes Bad (down since 2021-11-08 17:06:22 UTC)
Tags:32 AveMariaRAT link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-08n/aexe 0d005140631dfe917dd1f2796592471aea1062b3d7d0b29504fc1a61fc845e94n/a 
2021-11-06n/aexe 8be18831693382d4e44da33538200e46b153df34612fdb8f8d3afcdbad04b839n/a
2021-11-06n/aexe a22e23fe5c89cc0c76474af34136802b95b2df432ac52e065f6b29cee4b817a9n/a
2021-11-03n/aexe 792f8085698639794fbcbb4dfdb6c5eb6e9fe022443bd2b2f5a8dd542059e866n/a
2021-11-02n/aexe 60cdbe278baa2dea78ace57c7f1eda87f24c20985d345d12a2295503cc60244fn/a
2021-11-02n/aexe 9a8916e7a98924c2b36f9e40211093e78d57709e99d983dca42d3d1db7a78d60n/a
2021-10-29n/aexe e07327f2a5d54106bd1e7e877281080c57b320daaf69594794ce59ff69ae3761Virustotal results 48.44%AveMariaRAT