URLhaus Database

You are currently viewing the URLhaus database entry for http://91.92.241.168/download.php?pub=twointe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2748628
URL: http://91.92.241.168/download.php?pub=twointe
URL Status:Offline
Host: 91.92.241.168
Date added:2024-01-13 20:54:05 UTC
Last online:2024-01-14 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: andretavare5
Abuse complaint sent (?): Yes (2024-01-13 20:55:07 UTC to abuse{at}limenet[dot]io)
Takedown time:15 hours, 24 minutes Good (down since 2024-01-14 12:19:22 UTC)
Tags:dropped-by-PrivateLoader gcleaner link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-01-14twointeexe 13b1fcef292807ad431b2c2bb229584eca754b1d07444aec59e0a81279af3c96n/aGCleaner
2024-01-14twointeexe fb0661afe9e74716364e030d3c3c909afb06bc957d5599c6c5afb8b20385e979n/aGCleaner
2024-01-13twointeexe 6d85262730489297ec3d3051accf2dc5ad651df709dd0e2e154845544e601b0an/aGCleaner
2024-01-13twointeexe 1ae81612a07bd1a1f8e15cbf91f98d1d077702f92becebabc90631191ddf998dn/aGCleaner
2024-01-13twointeexe daa04918303463f10846507f938cc4f288de4119b710fad9dd894ddc3b383b0cn/aGCleaner