URLhaus Database

You are currently viewing the URLhaus database entry for http://147.45.44.104/prog/66b5d9d3adbaa_defaultr.exe#space which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3097309
URL: http://147.45.44.104/prog/66b5d9d3adbaa_defaultr.exe#space
URL Status:Offline
Host: 147.45.44.104
Date added:2024-08-09 09:01:10 UTC
Last online:2024-10-22 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-08-09 09:02:07 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:2 months, 14 days, 8 hours, 1 minutes Bad (down since 2024-10-22 17:04:03 UTC)
Tags:dropped-by-PrivateLoader exe njRAT link Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-16n/aexe a06b234cd7c15f51aff985fcc81c9c7937ac5a771824d0587129d036a65cd6een/a njrat
2024-10-14n/aexe 8479391fd94c7e2ffb67cb74a5c649aa2387a3b092aa8b45e090857b00760524n/a njrat
2024-10-04n/aexe 95574c8a8bfd865f789a4a28389c4791e25a928362d66436d5df9f34eb2e5935n/a 
2024-10-03n/aexe 44df34b21eaac4519ea7b7696a5babf0476156567bafa51ad7ebaa9d6db4920fn/a njrat
2024-10-01n/aexe df7d0e5d54c63af6de0427a3c55dea9acbbbeca61b3f03dc0a6042d209b45865n/a njrat
2024-09-13n/aexe ef43ef8e797eddbca9d683ce6c7d7e982f696b3d318212aa821546a625a2032fn/a njrat
2024-08-21n/aexe bfe5ba0f522808b1d8543b90f71bf4f329ca97a9edd4e8e790ee1a3829970a02n/a 
2024-08-17n/aexe 80e004ae420833a5ac777c953d54a3ad3f23dd77217ffe585513f70b4368e224n/a njrat
2024-08-09n/aexe b8a5ef9ea9fa588907a197db55c743559460190aa58b227db10d6be75d8bfe39n/aVidar