URLhaus Database

You are currently viewing the URLhaus database entry for http://45.9.74.80/zinda.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2717230
URL: http://45.9.74.80/zinda.exe
URL Status:Offline
Host: 45.9.74.80
Date added:2023-10-06 06:28:16 UTC
Last online:2023-10-19 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-10-06 06:29:19 UTC to abuse{at}lethost[dot]co)
Takedown time:12 days, 21 hours, 26 minutes Bad (down since 2023-10-19 03:55:53 UTC)
Tags:Amadey dropped-by-PrivateLoader glupteba link Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-10-12n/aexe 4458a9df5275bedd921127f4ff9dc63d4ac107f2e89cf46969e96f4c43d9f93eVirustotal results 86.11%Amadey
2023-10-12n/aexe 93ec2f65e8dcbd9bf755573667f9bc5d085e3533f1c0a67391fd2feed16899edn/aBackdoor.TeamViewer
2023-10-11n/aexe 2cf8ca0a1593e5ef380c8d8e9207f4257bbc4ef1ad2a5a5315f321ffecdc70ecVirustotal results 58.33%Backdoor.TeamViewer
2023-10-11n/aexe 96a8fc693eb17083f2fc31beffbbda57741ddec7b3ff38d29554a55bac7909a7Virustotal results 59.72%Backdoor.TeamViewer
2023-10-10n/aexe 5b6cd681c1cfcc56f59eeee0da6ffb47f5ea47450de63c6c42d3e49e2c6bfe5an/a Glupteba
2023-10-10n/aexe 78d20bb0f3344b725617819f4f2c2246a3c1d1cada81d931d63603f67a1b7aa7n/aStealc
2023-10-10n/aexe 62a9aacc321dd4fce52c04e97d42abe64cf08edc27cbc0b31e34fc6b28f6055dn/a 
2023-10-10n/aexe 5877e408a6db4b8619a2f6f75a58a9a0eb866e45614e1370bb6cabed7d375d36n/a 
2023-10-09n/aexe 8d833183ab5dcf4f622de22dd3bb6df752725339804906f7bb374b6df7c3c354Virustotal results 58.33%Stealc
2023-10-09n/aexe f9deeaaba4135cc9417f0a39a0b2860c88f91015cdee2dc8649f59800c5ef673Virustotal results 58.33%Backdoor.TeamViewer
2023-10-08n/aexe 98e2336afe9aed01d8859c988cb984a017800bf5a5760a643b9f5579c8936e40n/aBackdoor.TeamViewer
2023-10-08n/aexe 6fe8b12be78b3245026875ab2256a811c2000af5d7f21ffa7ea6c321f58f12d6n/a 
2023-10-06n/aexe 70af1a1c350554270883747e70ff85910cb2cc2c02d3ec133b4457100a05694dVirustotal results 56.94%Backdoor.TeamViewer
2023-10-06n/aexe fdec386da63058475415d75ff5a0c1e94095cf3ca17ea25d542baf2d26f04feaVirustotal results 59.72%Backdoor.TeamViewer