URLhaus Database

You are currently viewing the URLhaus database entry for http://192.3.164.126/dd/swift.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2517137
URL: http://192.3.164.126/dd/swift.exe
URL Status:Offline
Host: 192.3.164.126
Date added:2023-01-24 12:44:11 UTC
Last online:2023-02-17 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-01-24 12:45:07 UTC to reportabuse{at}racknerd[dot]com)
Takedown time:23 days, 20 hours, 56 minutes Bad (down since 2023-02-17 09:42:00 UTC)
Tags:AveMariaRAT link exe rat

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-01-25n/aexe f520f6f73efb0658ac2ee9c61cff3bc8d95f2ab0853ef6bee3edbdfb3db7d3fcVirustotal results 32.86%AveMariaRAT
2023-01-25n/aexe 4bdda49e98eae3912a4309ed3a0f7e861a83af656dbf91122c673e87f825ae45Virustotal results 48.53%AveMariaRAT
2023-01-24n/aexe c3e1f0d16ee92bd7a2ba925811eb5c60184908e91937d65d70addd7aa65643fcVirustotal results 56.34%AveMariaRAT