URLhaus Database

You are currently viewing the URLhaus database entry for http://91.92.241.91/files/InstallSetup2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2735609
URL: http://91.92.241.91/files/InstallSetup2.exe
URL Status:Offline
Host: 91.92.241.91
Date added:2023-11-27 16:20:11 UTC
Last online:2023-12-04 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-11-27 16:21:07 UTC to abuse{at}limenet[dot]io)
Takedown time:6 days, 23 hours, 31 minutes Bad (down since 2023-12-04 15:52:35 UTC)
Tags:Amadey CoinMiner dropped-by-PrivateLoader glupteba link Vidar link xmrig

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-12-04n/aexe f5be7905ff4e3fcff8697d08de785719c1eeac0d5ac5b8373917de764cc0cac1n/aGlupteba
2023-12-03n/aexe 8c05ce7f2040a7ea25080f7fa2b060052c1996dca83a3ea0c4b451cc1e16ced6n/aAmadey
2023-12-03n/aexe 894d4384548ba2e383a7568b57e5fcfd18d36dab8552142dd7f8c02457b9e4aan/aAmadey
2023-12-02n/aexe 90c705c231a5e9e61a41474b00d64b321e85df7f814b398fe11ba16287d98864n/aGlupteba
2023-12-02n/aexe ffd6e1c96829784a3a19881b1e0e65ed562671a0315f65750fab10dab81477e1Virustotal results 15.28%Glupteba
2023-12-01n/aexe eff416f17b83327e6911308b2b9678f52fb4b4d20b99a96f43c2478e5dcc10f2n/aVidar
2023-12-01n/aexe ae9dec17418ed06f57af2df42fc52c285416996c460115ad3a5d8929f0867951n/aGlupteba
2023-11-30n/aexe 347d793c12fd82dc8e0841d24d2f8cb9743534bd0f156b302b5cb7b07bb5d319n/aGlupteba
2023-11-30n/aexe b7cedaa26031eaa3bd108abb42e4a90738ca4606e7b305166b12a360f98cc251n/aGlupteba
2023-11-29n/aexe e7729036b9e69fd7dcf07e6ee0c8dd71a4b1432f55ab4e48572634de8d44b673Virustotal results 25.00%Glupteba
2023-11-28n/aexe 3e9c5961ee8a2a0c30539e79f9ddfb8870f5488d9571562fb1d90c8440dffdf3n/aCoinMiner
2023-11-28n/aexe 75f4bd481c7ee94f6e52fdb70de7db8243085067393a58ab14492452c4419297Virustotal results 15.28%Glupteba
2023-11-27n/aexe 90a3094c222cdadd6986b4d18e2c6ee5172484316ebd18a05167e2f458e17270Virustotal results 27.94%Glupteba