URLhaus Database

You are currently viewing the URLhaus database entry for http://193.56.146.77/ano/gala.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2432969
URL: http://193.56.146.77/ano/gala.exe
URL Status:Offline
Host: 193.56.146.77
Date added:2022-11-25 17:05:09 UTC
Last online:2022-12-01 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: viql
Abuse complaint sent (?): Yes (2022-11-25 17:06:07 UTC to info{at}janeiro[dot]msk[dot]ru)
Takedown time:6 days, 4 hours, 28 minutes Bad (down since 2022-12-01 21:34:57 UTC)
Tags:dropped-by-amadey LaplasClipper

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-27n/aexe 1c76b7e4eb0959b10adb0de26438ae70b64300d26437df95df5fc115f8cc57fen/aLaplasClipper
2022-11-27n/aexe a3bde8f159c8b68f5b84249258ff3bf4bc6594820bf25a053e4b61eb913aebd1n/aLaplasClipper
2022-11-26n/aexe 81e9eefec051e50a819e76fa1ec2f088c2e8c5de677537838193cf6c2e5c7584n/aLaplasClipper
2022-11-26n/aexe 11f2765287664a10a83b56cec5f2c1bf34ff7a7e1721458950d4976d54b21414n/aLaplasClipper
2022-11-25n/aexe 7dc8f90673b102c2945e36747763ccccd243519500eca01fd1cfdbbfcb61d61bVirustotal results 36.62%LaplasClipper