URLhaus Database

You are currently viewing the URLhaus database entry for http://77.91.124.207/DSC01491/fotocr20.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2615420
URL: http://77.91.124.207/DSC01491/fotocr20.exe
URL Status:Offline
Host: 77.91.124.207
Date added:2023-04-21 11:11:05 UTC
Last online:2023-04-22 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: viql
Abuse complaint sent (?): Yes (2023-04-21 11:12:05 UTC to abuse{at}altawk[dot]net)
Takedown time:1 day, 1 hours, 37 minutes Poor (down since 2023-04-22 12:49:56 UTC)
Tags:Amadey dropped-by-amadey RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-04-22n/aexe 514d7fdb59eb0225a784836750ff0d7f565cc8fc45a1417640e4d6dea3cd2cdfVirustotal results 48.57%Amadey
2023-04-22n/aexe 0f910fda9a2743b773a4d1272cc49b6d238ebab4262d25e8970a76061c52ab9en/aRedLineStealer
2023-04-22n/aexe 36108347fe6895016fba031c06791828e168f88c3199e683710874bd05173987n/aAmadey
2023-04-22n/aexe 1377436ef0011a1eb9b7d6951bc1087f2d8f8d75e0f945b71bd1e15bfe9c7bc4n/aAmadey
2023-04-22n/aexe bab5e3bf98211d2d290a8c912fa2699b8968fabc85b461e16b241bc7fba7c812n/aAmadey
2023-04-22n/aexe 4700b09654b2536a283c7692a03e837b52474e6ca4acef43293ca21a9c403717n/aAmadey
2023-04-22n/aexe e997c176edd591f2096f8eef48ca3d5f6939d7e859d30e03e28cc0129aef0853n/aAmadey
2023-04-22n/aexe 54c104b84feae2e6d742de8d38c60591341b5f692d7f03d212c0ad2681ed2e1cn/aRedLineStealer
2023-04-21n/aexe 4e47f3f3d862575dcfda3bcecc80dc39ebd007961bb6343ce3b5369044b02e30n/aAmadey
2023-04-21n/aexe 20f85916f0fcf158a51f426790f7e94e33709a3d87e103f4c817c2ed2c4d8c42n/aRedLineStealer
2023-04-21n/aexe 3acb0a322fd8facc64222e1a774f2152bd3c8568e53410a60a52e0aa14d3f805n/aRedLineStealer
2023-04-21n/aexe 2f5d54b041e6a8c3bffdb19bed589c840c5d6cfc9cb38f660af6248a15823bd0n/aAmadey
2023-04-21n/aexe c887032777f9d10acbc8aa4e166f3487a23fe1a542ea2d0ab139965bf83411a5n/aRedLineStealer
2023-04-21n/aexe 8efec08d76b263cf9af7f0ddf53710d88a1719b8b6970b965683b799cd4f7657n/a Amadey
2023-04-21n/aexe 6f2e01fede72f8af3674e97241754fab9cb782b65bbc36475a52acdd3206fca3n/a Amadey