URLhaus Database

You are currently viewing the URLhaus database entry for http://167.235.69.31/nppshell.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2532085
URL: http://167.235.69.31/nppshell.exe
URL Status:Offline
Host: 167.235.69.31
Date added:2023-02-06 13:22:12 UTC
Last online:2023-02-11 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: vxvault
Abuse complaint sent (?): Yes (2023-02-06 13:23:07 UTC to abuse{at}hetzner[dot]com)
Takedown time:4 days, 19 hours, 6 minutes Bad (down since 2023-02-11 08:29:41 UTC)
Tags:Amadey exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-02-08n/aexe 92c49bb49fa3ece278ef164a64bf1f41d0f4b3e632430ceb6a8da8d0d7b94e15n/a Amadey
2023-02-07n/aexe 4fa35d4f3b244508aa9959e907a3c6d5e5009dcf8ea77dbe76b7e3b5a43e1654Virustotal results 21.43% Amadey
2023-02-06n/aexe b34748df4525113b3dc212c943295b4c33ef7b956e89505fd5cf5fe66ee6845aVirustotal results 24.29%Amadey