URLhaus Database

You are currently viewing the URLhaus database entry for http://147.45.44.104/revada/66fa80c468fe3_Channel2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3202239
URL: http://147.45.44.104/revada/66fa80c468fe3_Channel2.exe
URL Status:Offline
Host: 147.45.44.104
Date added:2024-09-30 18:54:17 UTC
Last online:2024-10-22 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-09-30 18:55:12 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:21 days, 21 hours, 47 minutes Bad (down since 2024-10-22 16:43:05 UTC)
Tags:cryptbot dropped-by-PrivateLoader

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-20n/aexe 8574e3675b069689d47da02530aa3e5e12ab09cecf986ffc2635c33ed69cd9c6n/a 
2024-10-17n/aexe 222eca9f81ad01d2654af3c90001564e582dbdff4074889364ab461e3e7c91f0n/a 
2024-10-13n/aexe fdd8be2491979749f11899d6c735d62a57a0e4827af02f714e52dd75a401374dn/a 
2024-10-12n/aexe 0378698bd951797085aac34e7f8963fd9731ddadbb798745249d97f98c05568an/a 
2024-10-10n/aexe 2de133972835e57dba622fa0cc0ede18ef0930b8de25d12b53016a2dacdf649bn/a 
2024-10-07n/aexe f9e16ffe1a9a129351717f911f0efbe3fe483be6cb6e4830a6a2eedafd20532dn/a 
2024-10-02n/aexe d17121492ac694de62fda189c01d1dcca8ae0072c021cc48ab4d75ec03e06a76n/a 
2024-09-30n/aexe cb5f4641a3d416400f25611738e50f3cee8479c6d2c5ade6e4a2c36a14ac2e38Virustotal results 35.62%CryptBot