URLhaus Database

You are currently viewing the URLhaus database entry for http://194.180.49.153/udp/taskmaskamd.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2695438
URL: http://194.180.49.153/udp/taskmaskamd.exe
URL Status:Offline
Host: 194.180.49.153
Date added:2023-08-02 00:28:05 UTC
Last online:2023-10-31 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-08-02 00:29:05 UTC to abuse{at}des[dot]capital,abuse{at}serverion[dot]com)
Takedown time:3 months, 0 days, 22 hours, 54 minutes Bad (down since 2023-10-31 23:23:52 UTC)
Tags:32 Amadey exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-10-29n/aexe 6ed1c6da07e507a9399b64600162963763b8deb61fe55f7a3e1279eeeda63a2cn/a 
2023-10-23n/aexe 89f34a4b01bb06709003949e4fa6e73f15c98b04591c5fbddb824a5106465bf4n/a 
2023-10-21n/aexe d7b63be75e892fa2a049186268f46a7fa6fd116d8103c956f4d609906bdc56d2n/a
2023-10-03n/aexe f4065ed60e32da1ef0a82c7ce531edd05014d5b79fec26c26e078e80a876f916n/a 
2023-08-17n/aexe bed3fb5d8362bb67728ab4af4ae4f7f8f40390dfffb66b16f907ad8db29060cen/a
2023-08-12n/aexe 4b9d1edaea936f67387f42846014802d768ee548af10116d09c2ae253a61cdbdn/a RedLineStealer
2023-08-12n/aexe 49d073c438dd2e922ebebb413a2cf4d561bbbfd18c597dccee127e12ea19dbaan/a
2023-08-07n/aexe 164087c35475985bb9ebf4c52dee6459e71ad7ebf2ed0dccb04c5845097fe696n/a Amadey
2023-08-02n/aexe 9b6b6c5cf8dbafd06176a1f8e5a7cf7fc78a5ffb86df627e6de4eb455506b847Virustotal results 56.34%Amadey