URLhaus Database

You are currently viewing the URLhaus database entry for http://198.135.54.147:1088/1006/dllhost.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2359824
URL: http://198.135.54.147:1088/1006/dllhost.exe
URL Status:Offline
Host: 198.135.54.147
Date added:2022-10-11 04:42:05 UTC
Last online:2023-05-23 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-10-11 04:42:14 UTC to abuse{at}spinservers[dot]com)
Takedown time:7 months, 14 days, 10 hours, 38 minutes Bad (down since 2023-05-23 15:20:30 UTC)
Tags:32 Amadey exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-11n/aexe 81533cd917cbdacb7f2595156613a38656675c051e433dbac298a0ebc7b55820n/aAmadey
2022-10-11n/aexe 85cb960101e61833fb942afb57d7303584810ddfe28fdd912cbece0a103ff469n/a Amadey
2022-10-11n/aexe de58635edea0c31b96643d040464f29605f501b6f35c000d3e3f6f74a60c1900Virustotal results 40.28%Amadey