URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.75/files/GalaxySwapper/Galaxy_Swapper.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3440667
URL: http://185.215.113.75/files/GalaxySwapper/Galaxy_Swapper.exe
URL Status:Offline
Host: 185.215.113.75
Date added:2025-02-15 11:55:18 UTC
Last online:2025-02-21 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: Riordz
Abuse complaint sent (?): Yes (2025-02-15 11:56:04 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:5 days, 21 hours, 44 minutes Bad (down since 2025-02-21 09:40:59 UTC)
Tags:Amadey exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-02-16n/aexe 77a7bb456074c7332181c2d7113f0dfd26edc65c9e03bf1033ba44f58e9099f6Virustotal results 0.00% Amadey
2025-02-16n/aexe 05f2d45894b24006877bce19e7047e3111baae6b820bbbd95b0b86d592fb5d49n/a Amadey
2025-02-15n/aexe 1010e2f3d421ef21a3bb0450d95c97980ba750721d6ec487c2ed2700303733can/a Amadey