URLhaus Database

You are currently viewing the URLhaus database entry for http://77.91.68.1/new/fotod900.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2708244
URL: http://77.91.68.1/new/fotod900.exe
URL Status:Offline
Host: 77.91.68.1
Date added:2023-08-30 05:24:04 UTC
Last online:2023-09-04 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: Casperinous
Abuse complaint sent (?): Yes (2023-08-30 05:25:10 UTC to abuse{at}yeezyhost[dot]net)
Takedown time:5 days, 5 hours, 18 minutes Bad (down since 2023-09-04 10:44:09 UTC)
Tags:Amadey dropped-by-SmokeLoader RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-09-01n/aexe c1b80e36fff0fbce669fc8adf4b0e472d5d3ed1e7b0178495131002044f0ce4fVirustotal results 64.29% RedLineStealer
2023-09-01n/aexe 467345e55fbdd6fe693304427420db8d61b9fe44c06228da06427e816931b1bbn/a Amadey
2023-09-01n/aexe b63eeb616bba2e7df261a1a09550280b8367a846aff3a397914dc5ce93f495c0n/a RedLineStealer
2023-09-01n/aexe 03027719880d2949f7e45cbcf61dceae26e304d2fabb4d785030ccc7e087d818n/a Amadey
2023-09-01n/aexe d3aa4530838738e8b62c39dd5102875c05eb7bd9e46b850ef9acf3b58712e6b1n/a RedLineStealer
2023-09-01n/aexe 67a3926c00af0e197a03e92cc8aebd6a6ab4ef62ab5d98483b2f9f2060287081n/a Amadey
2023-09-01n/aexe 917a9a1d6f2901a757cdc92c5202c6940628825002ab5132ce1d5eb05f07ce47Virustotal results 63.64% Amadey
2023-09-01n/aexe f5e7e1e644a90e4caa16e41b356acacf0049cbfbd82d90fd9947ed9c550fd7d8n/a Amadey
2023-09-01n/aexe 7df04c85d76c9b0a2b155338dc4fe83e7dc829be31c7cf8dbb9a47e61ed1de93n/a Amadey
2023-09-01n/aexe 6576dbfd13419bb29f0e7d214a6a2451e97c4e23f2a0ac0a36c6f7f35fef952bn/a Amadey
2023-09-01n/aexe 936dea76e5cfa817cc2503012e0a17ce78d526e0d2908891a9413ce2bc6d22a2n/a RedLineStealer
2023-09-01n/aexe 2aa0fa90fb772b4d526663d8f56eb8b86ac7132a27b4644c0d331b0fe8f2404dn/a RedLineStealer
2023-09-01n/aexe c42b81cf9214011f1162ec48419176c3b1001f0005b959d64f55c51c4424bce1n/a Amadey
2023-08-31n/aexe e161e0acc9dd9cc39d7683ea07d038a66869637d980d5b178389c28c9761e175n/a Amadey
2023-08-31n/aexe 641166cd7d13ecf7b019cffa71ae9391accaa43fd42ba6f1cf9f1aecd91eb845n/a Amadey
2023-08-31n/aexe c2f5e5145600322dae2c00a5d05e9025f36dc8f04a02c988461b70e91a65f946n/a Amadey
2023-08-31n/aexe f1b4dbd163e818cbebd500f25f1f17ce56c65c86d010e54676eeea999dc95687n/a Amadey
2023-08-31n/aexe e8f7a35d5a7bdc7b7fdd5e911bb7609a45678bc0a286d6015fabe258e6bde220n/a Amadey
2023-08-31n/aexe b56afa0b66ca30fbadff867a9abc1bd56dc54eeeacce8068d403c9419a9e2cbcn/a RedLineStealer
2023-08-31n/aexe 7e6a9dca24e48ec7ceeddba66714cd2aa1fa8c5ec143a7854ad7c09068ba8c83n/a RedLineStealer
2023-08-31n/aexe fe627b89d037fe66fda73274e1eadf6e1cc6a3e43303791b7abfbf18eabb53a4n/a RedLineStealer
2023-08-31n/aexe bbf7e2cdca8ec7eb7524320925752f6230a150ca9763c6dac3201e85c09a1effVirustotal results 61.54% RedLineStealer
2023-08-31n/aexe 67f2a90ef0ab2b406ee7ce22a91f184650828f1944f05f541b7296f388d63713n/a Amadey
2023-08-31n/aexe 34e52bf50095ba26bf507692e5f2e65c93d51bb9c47a2fc2dcb5893dd2a8ae19n/a RedLineStealer
2023-08-31n/aexe 4a7aeed887e30c0859b2539d3d94997cf077caec6bbcabab077c1e8bd2316f5cn/a RedLineStealer
2023-08-31n/aexe 218135b00cdf562df24985c7f8837d4bea083caa07ee01411214621e8cc087een/a RedLineStealer
2023-08-31n/aexe 18431f64de2a26b34f9bd74c745855f37da7e60175a7c579e48efecb84827c1en/a RedLineStealer
2023-08-31n/aexe 6aef955180e12341fc953f84fa14291f2ab4004eed60e32f892a895a0c2e787fn/a RedLineStealer
2023-08-31n/aexe bab79b492d97010f552022e40d9db32e8cc8001ee328bc14df491d2300603910n/a RedLineStealer
2023-08-31n/aexe 545703504ea1ee6d11b94b1a151e93cad17d6087313de485276f25956a883674n/a Amadey
2023-08-31n/aexe 9492259b19029394753cf714721f8da060f67705b1e3f22e404f660b17a5eef0n/a Amadey
2023-08-31n/aexe 67d98733bafad01292b7a0c807396ed5588035741528ae26b9d5cbd173bbb4cdn/a Amadey
2023-08-31n/aexe e027d23f9b5c2e05b3f71cbb3f031fc21bf8729fbb00b87b0af8107754dc573fn/a Amadey
2023-08-31n/aexe aa1548b7252e7cc8725ea573fd71694224998ed768315c0b43579e1111ee0bd1n/a Amadey
2023-08-31n/aexe dfdcca7cef385f6342520cab8fe0a49868767b153fd00e256a0b542da7ddbffan/a RedLineStealer
2023-08-31n/aexe e5f80b28ee44b0bfaa402ef7b4923295fa483cbe4d98a1279cb15b6da9d19463n/a RedLineStealer
2023-08-31n/aexe 1c97b2efc82535cd2f95ec33308cb33287879eedbb8c48d53aca8fdad0fafc73n/a Amadey
2023-08-31n/aexe e954a8a41208a1eaca08f382ce5e2ad7b6ae254dc815513bfd0dfbcbd8f4bcban/a Amadey
2023-08-31n/aexe 21f9f10d6e54eda0278c2221bd60bc032dc9755da9bf02a2c6be95c30a951ddcn/a Amadey
2023-08-31n/aexe 8fed5bc031d3776d8b5f70235153a9e5000826ff4ab98b3172f592b584385fcdn/a Amadey
2023-08-31n/aexe 4b59f9f03cc6356ef20aafec102ae2ee730604e38a5c22a7b19dd8ed6446ab16n/a RedLineStealer
2023-08-31n/aexe d2ab888f1a4bc8da380430213989b91121612d6bb4c718fbf47a69d5f985a4fen/a RedLineStealer
2023-08-31n/aexe 3964a37f45cabeb21c4d2fd46c62ad0bf5901d50051cbbd668f3a0654ae7478bn/a Amadey
2023-08-31n/aexe 07cc241dcc0e530c8cf1b5311342c16ecc06453ee12aa033e34aa256bb0aed55n/a RedLineStealer
2023-08-30n/aexe 5433210d5138a2e1444606191b14b7323080a2af2434f5a6b5783d832d3adf03n/a Amadey
2023-08-30n/aexe 7bfe41924f59c59ea5f5b7c531ce144257741caa57c4f1e746b54ae73f73f874Virustotal results 62.50% Amadey
2023-08-30n/aexe f59ebf502ec0696ed6b734483c395f7934bf968cd6e86e11d504da41d782f59an/a RedLineStealer
2023-08-30n/aexe 71ebb324f711549202f2c3e5658b85777cee34021ffb646cbb016dcf5f922d48n/a RedLineStealer
2023-08-30n/aexe 2b1ef47778d4099c6d82ddd8ef73ea376bf55194151ad704f9a08b6226da2033n/a Amadey
2023-08-30n/aexe 3276e6469cae3a0b7e35eb56f7a0e5c70d2a0dd7580d21401a0ce8d2fd0a584an/a Amadey
2023-08-30n/aexe e3cbd6233f050e9f4e700456db2112b544d4262bfaa242dd0d2d6f598a7f3150n/a Amadey
2023-08-30n/aexe 5e46baa5f814822a92a464e10bf3d52e426cadca2b8705af7bb9de52334345c1n/a RedLineStealer
2023-08-30n/aexe cdfdee98460810c61008253dc1ce739d6f8ac5e0559ead830fa3d82e8be7449bn/a Amadey
2023-08-30n/aexe 1cbae2053cb2985af53dd9f730bb40ac9a0c36800fc88f73cd5a95b30c50fe96n/a Amadey
2023-08-30n/aexe 0f626a5324b42e60630fc309104971c812530f8671d745dc246261032db604d0n/a RedLineStealer
2023-08-30n/aexe 5cc747079e218758e614ab41645f4c70d6e74fc0b132bdd231ee6422088e5254n/a RedLineStealer
2023-08-30n/aexe d9dfacbc3c897438dfab93a849665242abd3d124e43846f0b105108a836b72cfn/a RedLineStealer
2023-08-30n/aexe 2e41c62edf36284c12cea91576a393d313d9cb633169ed8dbcbbb98bb0b27879n/a Amadey
2023-08-30n/aexe dcfc177cfea5496fe8b5f929a861b3dcc69b3924f0c6c4de033229432f6c268dn/a RedLineStealer
2023-08-30n/aexe d7b425fd73b652cc401384df349d3204cc88570b5bfd2f717fdbcde78ee2d47cn/a RedLineStealer
2023-08-30n/aexe f6f90d984f767ca4d9a2d430d1383c5b180c4d0aca67e2572f16fa842e909432n/a RedLineStealer
2023-08-30n/aexe ca3ddb2ee963f8ce3067b5d16691245cee88ffa9ee89b8d2480b49aaecc176a4n/a Amadey
2023-08-30n/aexe 45159003206fdfa70bc9f63631805ec05930a77add8b0fd14140b27fda70108cn/a RedLineStealer
2023-08-30n/aexe 44f69b5f6c134124c3d52902f5fa6194724d997b30bc4a7bbb9fb174c60931e8n/a RedLineStealer
2023-08-30n/aexe 80c963d7cea25d27ef4365c2be78d31a0fc50da481408c1135b820ed540f96a4n/a Amadey
2023-08-30n/aexe 001fe57fedfc00df6711098dd213efae8cd36711b3ad403e8ab31f0070a4ef6fn/a RedLineStealer
2023-08-30n/aexe 8e43563c4ed06ebe8d29e25bbbe0aa71eac95457c64997cd617566989b7f2bf8Virustotal results 60.00% RedLineStealer
2023-08-30n/aexe b542b1dfb4773dad3651604e2637e55ff5853c16374c9ce8affbd9f25067417dn/a RedLineStealer