URLhaus Database

You are currently viewing the URLhaus database entry for http://77.91.68.1/new/fotod200.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2709457
URL: http://77.91.68.1/new/fotod200.exe
URL Status:Offline
Host: 77.91.68.1
Date added:2023-09-04 07:40:08 UTC
Last online:2023-09-10 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: Casperinous
Abuse complaint sent (?): Yes (2023-09-04 07:41:05 UTC to abuse{at}yeezyhost[dot]net)
Takedown time:6 days, 2 hours, 58 minutes Bad (down since 2023-09-10 10:39:42 UTC)
Tags:Amadey dropped-by-SmokeLoader RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-09-04n/aexe 3296d26ab7a111dbf86d9899636d80e04e285966d7991b6302ef2a08e61b9263Virustotal results 64.79% RedLineStealer
2023-09-04n/aexe f27143c49f24db6050f853d456683a42fc213ef119c7df8decc5dbd4184d48fan/a Amadey
2023-09-04n/aexe cb31a9837f194a85e775d9da74f00dc4e89eb664f2861945421559384e090771n/a RedLineStealer
2023-09-04n/aexe cc0d3bf3f4416da1a8d8d179e85f86847cde13a1fac517bcaa0ff1c5610c46f3n/a RedLineStealer
2023-09-04n/aexe a8b6c506e1a5b1b80935138a6905e524cd41c706219b8eaee62affd09056948fn/a RedLineStealer
2023-09-04n/aexe d72b24baf975e8d4b09a41b9e1c56064c637b7e9059397d69fc7b5d497f588e2n/a Amadey
2023-09-04n/aexe ad1cd0b03abfbfd28a5388602b26041af4c2f030ff37024b1ba675c88347e552n/a Amadey
2023-09-04n/aexe af460ab225037096408c1de3f2dbde7cde729669941d6fe0ccffb42991b8489dn/a RedLineStealer
2023-09-04n/aexe 26bc4a2f0de50ed86b27de0f91f6115dee84aca9bec236ecd5f355167bf84a64n/a Amadey