URLhaus Database

You are currently viewing the URLhaus database entry for http://185.196.8.238/amarer.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2733638
URL: http://185.196.8.238/amarer.exe
URL Status:Offline
Host: 185.196.8.238
Date added:2023-11-22 03:32:06 UTC
Last online:2023-11-30 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-11-22 03:33:05 UTC to abuse{at}simplecarrier[dot]net)
Takedown time:8 days, 1 hours, 47 minutes Bad (down since 2023-11-30 05:20:15 UTC)
Tags:32 Amadey exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-25n/aexe 8d2a84ab2b65a861fee39dc425e72588cd9f08638c9e982c7797218f2a326afan/a 
2023-11-23n/aexe d9419bc56421da78118cd511468bbc463bfb2c8d4405e2a6b38956b5a49d10a3Virustotal results 16.67% Amadey
2023-11-23n/aexe 138b791bb04c3073e3e752fdcf5bc5490c4169e9f553954b025aab8414c4589aVirustotal results 43.06%Amadey
2023-11-22n/aexe bb150377b93d4df2a877a68e700490644290a0ea59001c189e55bbf62bad1e68Virustotal results 36.11%Amadey