URLhaus Database

You are currently viewing the URLhaus database entry for http://37.220.87.53/xkrxxm.t5ky.static3.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2544988
URL: http://37.220.87.53/xkrxxm.t5ky.static3.exe
URL Status:Offline
Host: 37.220.87.53
Date added:2023-02-19 17:07:04 UTC
Last online:2023-03-01 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-02-19 17:08:05 UTC to abuse{at}lethost[dot]co)
Takedown time:10 days, 4 hours, 42 minutes Bad (down since 2023-03-01 21:51:02 UTC)
Tags:exe Rhadamanthys

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-02-26n/aexe 168463cc82b802ba7d0b28ae9ad798644cc548ebb622991e7eac6ecf87c3ab99n/a Rhadamanthys
2023-02-22n/aexe 018dce4f1662e4a8acc443b2f70232b2d3e6586409c71052ca86331525593285Virustotal results 42.86% Rhadamanthys
2023-02-21n/aexe 889a440afd7fb1f5eb0951772611d04ff2b2668dea045aa71e82ced0093a920en/a Rhadamanthys
2023-02-19n/aexe 771b17a6dd0415a8bb28084f8e4690e0ac0e42e5bac15dfd988e836253e0cb04Virustotal results 30.00%Rhadamanthys