URLhaus Database

You are currently viewing the URLhaus database entry for http://192.3.26.135/765/g8cs.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2554572
URL: http://192.3.26.135/765/g8cs.exe
URL Status:Offline
Host: 192.3.26.135
Date added:2023-03-01 19:02:04 UTC
Last online:2023-03-16 01:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-03-01 19:03:05 UTC to abuse{at}colocrossing[dot]com)
Takedown time:14 days, 6 hours, 20 minutes Bad (down since 2023-03-16 01:23:35 UTC)
Tags:exe opendir SnakeKeylogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-03-02n/aexe 8bb4628c5c061cdc9ed4b64c5ef73d57d882b3fc218c171b7650f1803b3545fdVirustotal results 13.04%SnakeKeylogger
2023-03-02n/aexe c1c2c7f68cd6257da48226477b7be1b3d82b9f6ee7b1e421b7b9d5191f89c8c6Virustotal results 22.86%SnakeKeylogger
2023-03-02n/aexe a539cbe05c220c5a791f2581c2a306273a9d954868428bffd1b01d2bd2fa721dn/aSnakeKeylogger
2023-03-01n/aexe 9a8ec6a91a6416d3162fb0de7437a670eacb64b1d10bf1674afa27ad60a8415dVirustotal results 16.95%SnakeKeylogger