URLhaus Database

You are currently viewing the URLhaus database entry for http://193.3.19.114/u8v5zeQ/Plugins/cred64.dll which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2727885
URL: http://193.3.19.114/u8v5zeQ/Plugins/cred64.dll
URL Status:Offline
Host: 193.3.19.114
Date added:2023-11-04 19:30:10 UTC
Last online:2024-04-18 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-11-04 19:31:06 UTC to abuse{at}changway[dot]hk)
Takedown time:5 months, 15 days, 10 hours, 55 minutes Bad (down since 2024-04-18 06:26:14 UTC)
Tags:64 Amadey exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-03-17n/adll 883860b5a67d28af4dd633886ba05187edd158744451d6b855f145a669a8c74an/a 
2024-03-16n/adll 20531ffc27c3b27589aa8c67befd8dbfb52dccdd843b05dfe703a774598c8a38n/a 
2024-03-15n/adll 96aa65c8f0f775bbda708860fe8bffdc1a652563f536c2be5066adc40e54cfddn/a 
2024-03-15n/adll 8d936eb0efa81c340b315401a103836ad4bc1e835f7157e2d2410aba16070510n/a 
2024-03-14n/adll c26cec9510b6599d33a9496fe3d1ac896adcd55c6ae762b3d5ab45a12640cab6n/a 
2024-03-14n/adll 9a4d38d12b507ead93c413791f28f49120f4d5f8dfd3118d9165a1f799d40908n/a 
2024-03-14n/adll 83001ca887e236c66ba61172d9a5fc8d01a079fa008c51b9bb89fd5aa2d288ean/a 
2023-11-04n/adll c33c79018a633d26f4c4d780ff49aec28a560dd65941845b060bde1f109d97e0Virustotal results 38.03%Amadey