URLhaus Database

You are currently viewing the URLhaus database entry for http://147.45.44.104/malesa/66ca202b71c36_HP.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3126504
URL: http://147.45.44.104/malesa/66ca202b71c36_HP.exe
URL Status:Offline
Host: 147.45.44.104
Date added:2024-08-24 18:07:21 UTC
Last online:2024-10-22 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-08-24 18:08:06 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:1 month, 29 days, 0 hours, 0 minutes Bad (down since 2024-10-22 18:08:31 UTC)
Tags:dropped-by-PrivateLoader exe Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-13n/aexe 684327f3187a5d8d15c0339a7bc1d618a89a06d468203380cf6fac04df76b5c3n/a Vidar
2024-10-12n/aexe 85252a91fc8de7022f58393f37101793d331515788042244c09a8c4b3d67293bn/a Vidar
2024-10-11n/aexe 7bea93b459e1784133bb7b161b2373de1b084e4e2c59e3d354a59aa7f2553056n/a Vidar
2024-09-28n/aexe 2d28a26e75c621a1b31205103e160ab8de6791466f4eaece70427fcae4eb45d1n/a Vidar
2024-09-28n/aexe 81efbe1f3a72ae760f7a1d6b8abfa9e0d590a4da8fd0469902cc0ea0bb7d586bn/a 
2024-09-16n/aexe 0932fe32e376c92f7f356e0d3d1be4772169917d3e76da65f48c8ee906c53969n/a Vidar
2024-09-10n/aexe 070a7dd16cdc2c0990ddac5c9881e12bc01046d2679a5945dfebaaad6e7eec1bn/a 
2024-08-24n/aexe dbbacaf728af45c13e7aa9538090d6795d4fa7ace887d6f0823007a55414a1a1n/aVidar