URLhaus Database

You are currently viewing the URLhaus database entry for http://194.49.94.67/files/InstallSetup2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2729008
URL: http://194.49.94.67/files/InstallSetup2.exe
URL Status:Offline
Host: 194.49.94.67
Date added:2023-11-08 13:03:06 UTC
Last online:2023-11-12 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-11-08 13:04:05 UTC to madhost{at}tutanota[dot]com)
Takedown time:4 days, 7 hours, 12 minutes Bad (down since 2023-11-12 20:16:30 UTC)
Tags:Amadey dropped-by-PrivateLoader Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-12n/aexe 57a7963f89e7bc17d95510a7e6932bc8bd519a29cf5b249442d58c72c385ab51n/a 
2023-11-11n/aexe ba5c2fdd986bceda30daf8e5f32a9d01532882d51693739169620f371dbde0baVirustotal results 37.50%
2023-11-11n/aexe a7d88aa73555c7d6c46fdb47ec98d259c853c8356c46da573d5854e9798d7575n/a 
2023-11-10n/aexe f36fc8e0bb8eab645cf6b4876e588dc427575a4fb25db629598b29f1d9328756n/aVidar
2023-11-09n/aexe 49eb7ae3dc1471e864bd0daa995ec894961dcf307354d37b675a01adbcba6490Virustotal results 15.49%Amadey
2023-11-08n/aexe 304297cf4b97fed416f783c13df6b4718414e78ac9f07b7b0ad1ab9c528a57c7Virustotal results 32.39%Amadey
2023-11-08n/aexe 79a129abb141286ddc2af3ad937773a10701215cbff6b26a8b2217aa95c1c66cVirustotal results 36.11%