URLhaus Database

You are currently viewing the URLhaus database entry for http://77.91.68.63/DSC01491/fotod95.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2671929
URL: http://77.91.68.63/DSC01491/fotod95.exe
URL Status:Offline
Host: 77.91.68.63
Date added:2023-06-26 05:53:05 UTC
Last online:2023-06-26 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-06-26 05:54:05 UTC to abuse{at}yeezyhost[dot]net)
Takedown time:9 hours, 31 minutes Good (down since 2023-06-26 15:25:26 UTC)
Tags:Amadey exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-26n/aexe 9fe05597cab820a7c47100e536667a2b8aa63d17e49cdbe84b1c81e3d75d1b98n/a Amadey
2023-06-26n/aexe 75d5f8312e7882c0c2cc97c6b4bb29252ae07cc85235eb7045984a89b99b3b25n/a Amadey
2023-06-26n/aexe 27216887e9d0a5a5ab9cb5eb5556cdd847060a7b790b5a9c9f8817d3d01da56en/a RedLineStealer
2023-06-26n/aexe bb097149af823888c039616778153e8c17a3b8049448c0fa8ad06c4793c44104n/a Amadey
2023-06-26n/aexe 32fd42319d5c0adf926049a63e6241ad87e4a7fd8c551e0bd8cd0ed36292bed8n/aAmadey
2023-06-26n/aexe 17e6f63c508790177d15511c2320e4ce23f24a43f02b5f26f79d3a9aba258630n/a RedLineStealer
2023-06-26n/aexe 895d2a6d4e623c3a008a3cbf8708c20447727393f53d4dbfe3ddd3d7d7bfb199n/a Amadey
2023-06-26n/aexe 8433d9a79676cb17f1fbe3e8cce8d72028a89b4b9f32a077c78cc576f4313b69n/a RedLineStealer
2023-06-26n/aexe aad27598d848cfb299c437cf0081c22fddefbcb3fd4edeb78c785b51c941684dn/a Amadey
2023-06-26n/aexe 24718657e41a4b825c1f1c7df68cf92d68ab3b2956b8854a2d85ca7a742d6038n/a RedLineStealer
2023-06-26n/aexe f7fbc365277a3f045b6b33041dbd65fe3090ef5606e53e8fee8a9d9677596b8en/a RedLineStealer
2023-06-26n/aexe eeedeae7640e8f8567fd87ae7e8782ba80d1ee60e46def68ab1e7c0d668acb50n/a Amadey
2023-06-26n/aexe c6a5232a26561cc69308f9b5b6d68e0a579af744cedc34f7b03f4c554fd63e7fVirustotal results 30.99% RedLineStealer
2023-06-26n/aexe a63793686b62120a1243e1503c1befa02b6feee88d18acdb0f0b28a50591fbe3n/a RedLineStealer
2023-06-26n/aexe f6e28cfbb194f922bcd16aa88fbd64b9936057b48a2ac6823229380e542904e1n/a Amadey