URLhaus Database

You are currently viewing the URLhaus database entry for http://193.233.132.167/enigma/Plugins/cred64.dll which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2755265
URL: http://193.233.132.167/enigma/Plugins/cred64.dll
URL Status:Offline
Host: 193.233.132.167
Date added:2024-02-02 06:15:18 UTC
Last online:2024-05-01 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2024-02-02 06:16:07 UTC to abuse{at}sunhost[dot]ltd)
Takedown time:2 months, 29 days, 14 hours, 56 minutes Bad (down since 2024-05-01 21:12:23 UTC)
Tags:64 Amadey exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-03-18n/adll 9d932a1ca90400c7ec11bb21029d3c4873b1b092c057a7331f02457c734e2da7n/a 
2024-03-16n/adll a3facae0752c3c92270b6da9a289d66f3f45a8125f1c2a5e5d4b1a1fb3f4de91n/a 
2024-03-14n/adll ccbf80ff032d435a5b903e4ce6c9d4c1a98fee26d1d7d6b50bf6f1e6f4b70a39n/a 
2024-02-02n/adll 83e3df5bec15d5333935bea8b719a6d677e2fb3dc1cf9e18e7b82fd0438285c7Virustotal results 50.70%Amadey