URLhaus Database

You are currently viewing the URLhaus database entry for http://185.106.92.187/shared/Ruzvelt.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2603280
URL: http://185.106.92.187/shared/Ruzvelt.exe
URL Status:Offline
Host: 185.106.92.187
Date added:2023-04-09 07:43:11 UTC
Last online:2023-04-10 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-04-09 07:44:06 UTC to abuse{at}waicore[dot]com)
Takedown time:16 hours, 40 minutes Good (down since 2023-04-10 00:24:54 UTC)
Tags:exe opendir Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-04-09n/aexe db7d183bfb8be509bd2adc8995a949e8b7ee0de1ea4f616fc1a7d556c9edda08n/a Vidar
2023-04-09n/aexe 6456991a9a5edbcd966034c7a2f70f85dbdc23a68a22d79a6917e25ea4b491ean/a Vidar
2023-04-09n/aexe 51c58fb525b4136f63f5e013dcaf70e6b5d6918bc4b0c66c78beeeeee39513efVirustotal results 49.28%Vidar
2023-04-09n/aexe c3e84add526ff6bdb23e791ea5d2c5631bbab1374b48c9b1bb04cbb5a3b76cf4Virustotal results 48.57% Vidar
2023-04-09n/aexe 5abf1c8851ee76460da6b34fa8256fc1ee3694f0186a50b860942467b6744130Virustotal results 48.53%Vidar
2023-04-09n/aexe d734282446d43905057238533fccc19bddeccc3e1e82354d7077c9372a8780d2Virustotal results 47.14% Vidar
2023-04-09n/aexe e262640618fa7f6e57b8858778aabe3a0f4420541d4c9dd11c064f20998c10e7n/a Vidar
2023-04-09n/aexe 83ccbc8aef4eb5fb8840b73fe03fd47aeef80c6864dad75cb702e67c47e085e4Virustotal results 50.00% Vidar
2023-04-09n/aexe 9ce18c132b08a551620f39de290ddbd2b862a2f240e65e8ae9086f7b92b2f075Virustotal results 47.14%Vidar