URLhaus Database

You are currently viewing the URLhaus database entry for http://77.73.134.248/roma/final.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2399013
URL: http://77.73.134.248/roma/final.exe
URL Status:Offline
Host: 77.73.134.248
Date added:2022-11-03 11:40:05 UTC
Last online:2022-11-04 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: andretavare5
Abuse complaint sent (?): Yes (2022-11-03 11:41:10 UTC to abuse{at}lethost[dot]co)
Takedown time:13 hours, 11 minutes Good (down since 2022-11-04 00:52:43 UTC)
Tags:Amadey dropby PrivateLoader RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-03n/aexe 402919562ebae8f53c3a0c9215dd90db5adcb1a14db34021696fd1f331c8fa97n/aAmadey
2022-11-03n/aexe ae0f14d26c824dcaf4a51841da9eedf692b6bbe90ffd212aa2852e826d671829Virustotal results 38.57% Amadey
2022-11-03n/aexe 075dc64d459de82f22a3200e1db2e52ee6353aff2be42a9e240dbdfd4cb668b3n/a RedLineStealer
2022-11-03n/aexe 63e34103a44fe13c98370e973e6c8ea4d62b369a6dc61bbb61c0ce45911f846bn/a Amadey
2022-11-03n/aexe 2a28b4be765aa057552c83b7f0ffaeee7d545f5f3ad0852e3cfa9774943c959an/a Amadey
2022-11-03n/aexe 01b71e7ff970940dd98fedf24a11cfcb0887c2159a9b849bb8ce0d33ce661110n/a Amadey
2022-11-03n/aexe e5bfeffc940eed599fceadcf2093422d418aaec7a750099ced752c0ae8a96454n/aAmadey
2022-11-03n/aexe 922bceda5803b7a00c27746a89ac60fb6ad433ec7cc23860fd95eb88a2b99338Virustotal results 36.62%Amadey
2022-11-03n/aexe ff19ee64e7a879f30f53454f565f2f4ad85f0e74577e64d9f9e946e895feb0beVirustotal results 38.89%Amadey
2022-11-03n/aexe 920c79936fdd6d86862f3655c0fb35192b3716226022321701260b524536c7a6n/aAmadey