URLhaus Database

You are currently viewing the URLhaus database entry for http://79.137.194.203/umciavi32.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2543104
URL: http://79.137.194.203/umciavi32.exe
URL Status:Offline
Host: 79.137.194.203
Date added:2023-02-17 16:31:07 UTC
Last online:2023-02-20 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: viql
Abuse complaint sent (?): Yes (2023-02-17 16:32:05 UTC to abuse{at}aeza[dot]net)
Takedown time:3 days, 0 hours, 47 minutes Bad (down since 2023-02-20 17:19:40 UTC)
Tags:dropped-by-amadey rustystealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-02-18n/aexe a365358a1e58a2f611eafbaa258810e910a1830de96e552950a2057f7617de35n/a 
2023-02-17n/aexe 73df61e5b857a42a63edb57a71aba2892a731048fe91c8b9d3e40d989a8fdcc1Virustotal results 16.90%RustyStealer
2023-02-17n/aexe b86a7f4e904243a5018bbc43d55bcf47d8157ce6c22df7800cff0fbca0859d39Virustotal results 18.31%RustyStealer