URLhaus Database

You are currently viewing the URLhaus database entry for http://77.73.134.249/vr/Galaxy.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2389554
URL: http://77.73.134.249/vr/Galaxy.exe
URL Status:Offline
Host: 77.73.134.249
Date added:2022-10-28 18:03:05 UTC
Last online:2022-10-30 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: andretavare5
Abuse complaint sent (?): Yes (2022-10-28 18:04:10 UTC to abuse{at}lethost[dot]co)
Takedown time:1 day, 15 hours, 9 minutes Poor (down since 2022-10-30 09:13:50 UTC)
Tags:Amadey dropby PrivateLoader

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-29n/aexe 675821978a7bbc35c58cab72b68f25ca29ba86c5850f185b805ee45b8f1e57c4Virustotal results 33.33% Amadey
2022-10-29n/aexe 7924ee6456a194753ef284db579a5cd6ef39c65127fe27e597b498bac14984ban/aAmadey
2022-10-29n/aexe 104dadd518df140c463cf2dfdaa6bfd79f56c9a98489a3f04021b74b4d75ebb4n/a Amadey
2022-10-29n/aexe 930587f2fce5a9b9c6f913aba611fd0656351fa892306b48ba3908aa91b9130an/a Amadey
2022-10-29n/aexe d72b9feb15dfcf386661eb74f5abfd21e4a6ac80a9ebfa26b388fa07a78973ean/a Amadey
2022-10-29n/aexe 06ee8d839f66c6fac1ced7b68edf6b95563fa8419bd2136853b14bfbe9951570n/a Amadey
2022-10-29n/aexe 8029d594b7d98abab5746cab8907dd0e582200e1edc96435875d16e80b6f9fa8Virustotal results 35.21%Amadey
2022-10-29n/aexe e4b50fa211028e2911ddcf8c8a4e9f508574625223dc6f266311d0de64cd30a0Virustotal results 33.33%Amadey
2022-10-29n/aexe 126fbb91769df655bd067c24a31281e7a25432debd4901c216575bd5a48277c7n/a Amadey
2022-10-29n/aexe 3b3e5ebbd2624aec52ac86de4f237c7840aaac79afc90c9bb85f964285c4c056n/aAmadey
2022-10-29n/aexe fb6f40cde082ac3f00870f41896921f1cac37324c3bfc136d4a89230f79abbb0n/a Amadey
2022-10-29n/aexe 3d0a24492ab7818a9ece57f64f0d30989664a5f84f76166f5abc65148253f613n/aAmadey
2022-10-29n/aexe 2279ef46675d8bf653814f9de3a817e686bbc3ea8f8d1896392af0a8ce620cddn/aAmadey
2022-10-29n/aexe 12a71166aa4d5fb6054d6e24c777e1b3ab9d10f340967a62d7f141dd79370450n/aAmadey
2022-10-29n/aexe 22bac35fd3b8d109440ddf8dc045b9ee46e1f75c46dade2841b77248df2fbaa9n/aAmadey
2022-10-29n/aexe a7d04fb1606e8cfdaaa9a98742e49f80fc9c650affdac46ac34539de96c3567bn/aAmadey
2022-10-28n/aexe 56e6ea95e921b3add1bbc000ca980ae65abc81c620ab2c76795660b671500408n/aAmadey
2022-10-28n/aexe e75b6eeeab3631bb5132ff5d8b37274761c9abde15d76c853a8dbd8ce811c46bn/a Amadey
2022-10-28n/aexe 2362d77a533e3c791d6c0475886bd2a3ca81180834c99862f3626db1122078d1Virustotal results 43.66%Amadey
2022-10-28n/aexe cf95dca92b0825e77760fdce4714de6aa1f53a157c5b7a8fe55051f5cb44b969n/aAmadey
2022-10-28n/aexe b0b4664013262a48fa9543ed9c651c34c9a7233678882f16d86e779c0a9a39can/aAmadey