URLhaus Database

You are currently viewing the URLhaus database entry for http://195.201.23.180/urapwd2x.dll which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2532082
URL: http://195.201.23.180/urapwd2x.dll
URL Status:Offline
Host: 195.201.23.180
Date added:2023-02-06 13:19:10 UTC
Last online:2023-02-11 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: vxvault
Abuse complaint sent (?): Yes (2023-02-06 13:20:08 UTC to abuse{at}hetzner[dot]com)
Takedown time:4 days, 18 hours, 44 minutes Bad (down since 2023-02-11 08:05:06 UTC)
Tags:exe RaccoonStealer link RecordBreaker link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-02-08n/adll 0b0a847563b9c7f7b8e12f322969ed4d50deb5046b3e3329dc0dbccb9c489450n/a RecordBreaker
2023-02-07n/adll 18656125ea784a55b38328f01cb4699b50d1548d701730c9ca3e938c4e9d8e54Virustotal results 18.57% RecordBreaker
2023-02-06n/adll b06c5fb7651b8a6c683b62babcabd18da4d992f7d1e0f963c530832b18feacf4n/aRecordBreaker
2023-02-06n/adll 887d6ad4cffeedfd403427c94439bcb265e54d86e0166956bb978cfa24c55c27n/aRaccoonStealer