URLhaus Database

You are currently viewing the URLhaus database entry for http://77.73.134.27/race.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2518982
URL: http://77.73.134.27/race.exe
URL Status:Offline
Host: 77.73.134.27
Date added:2023-01-26 11:39:04 UTC
Last online:2023-01-29 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-01-26 11:40:07 UTC to abuse{at}lethost[dot]co)
Takedown time:3 days, 10 hours, 21 minutes Bad (down since 2023-01-29 22:01:50 UTC)
Tags:Amadey drop-by-malware PrivateLoader RecordBreaker link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-01-29n/aexe 0c346b8657a834a536575fb82a6b9ee37c738547fb2e4de821917d9131ec3fe2Virustotal results 48.57%RecordBreaker
2023-01-29n/aexe 47441e1d63c39f1ef422b3b073c68e8ad740070404c9a2f0c5e9e3910440092en/aAmadey
2023-01-29n/aexe b56d9fb1c1115ea938528713be7de446276c1829b65e15f116ff5837a71dc787n/aAmadey
2023-01-29n/aexe 101ba2d4e3f712d221bfff7db1ea59082fe064cf8cc541e20dd272859c372c14n/aAmadey
2023-01-29n/aexe cb8cd78c09c1a9dd7b2cf6a4288c984b4b5619ab8301d1a963e089024bb314d0Virustotal results 55.71%Spambot.Kelihos
2023-01-28n/aexe 2c18cc487d7d1078460dce7e68108cb99eab6cb9ee1955ca4df3b2376f0a0e8bVirustotal results 58.57%Amadey
2023-01-28n/aexe e115bc4b1111389c8394d798d55a95c2181ac088fbea26c62645d3d82884dd54n/aAmadey
2023-01-27n/aexe 2e09674fc46e09a14bcfc5e3078de72c91c17d6fd3aac5146677cbe94a784d24Virustotal results 55.22%Amadey
2023-01-26n/aexe 497251504b3852147d2fb7d333ff1f045a74ee4c3ddbcf80b700968a4a8863dbVirustotal results 61.43%Spambot.Kelihos