URLhaus Database

You are currently viewing the URLhaus database entry for http://114.132.245.93/server.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1830421
URL: http://114.132.245.93/server.exe
URL Status:Offline
Host: 114.132.245.93
Date added:2021-11-29 01:30:06 UTC
Last online:2021-12-14 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-11-29 01:31:04 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:15 days, 4 hours, 56 minutes Bad (down since 2021-12-14 06:27:53 UTC)
Tags:32 exe younglotus

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-11n/aexe 81c8407852e8e6af7a2f31f6743c5d9eae11962a5a1682c15e663364b9a9b986Virustotal results 20.90%
2021-11-30n/aexe 0bb41d2016dee94d1070270342cd5786440d71474894d73391ee75b12695165en/aYoungLotus
2021-11-30n/aexe 2ea81891e23bcd72cdffb06cd01592b02f72fabc73ca3e5eba224ef055f4aca5n/aYoungLotus
2021-11-29n/aexe 4cdabf346e79baa2efe9c70b359a1b4366b16e0de4aa4984d92aeb08ae2a71e8Virustotal results 39.39%YoungLotus