URLhaus Database

You are currently viewing the URLhaus database entry for http://217.8.117.76/tools/ports/apps/cred.dll which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:322135
URL: http://217.8.117.76/tools/ports/apps/cred.dll
URL Status:Offline
Host: 217.8.117.76
Date added:2020-03-06 13:00:04 UTC
Last online:2020-12-08 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2020-03-06 13:02:03 UTC to abuse{at}grandcosmetic2[dot]ru)
Takedown time:9 months, 6 days, 18 hours, 31 minutes Bad (down since 2020-12-08 07:33:11 UTC)
Tags:Amadey

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-29n/adll 760ea37a70dc258db13d1b3c6993de70d35cab20d4049cb427c7bfe3103ef1fcn/a 
2020-05-02n/aexe 8437af9312fa3a3f5ed17a5b1877502024832eb2b050fb93566389817c47f551n/aAmadey
2020-03-06n/aexe 6bf0943fdfef0553a5259665aba351755ecabb70e29d6fbd290aa80bdf525b9fVirustotal results 37.14%