URLhaus Database

You are currently viewing the URLhaus database entry for http://91.200.14.153/Downloads/window.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3533796
URL: http://91.200.14.153/Downloads/window.exe
URL Status:Offline
Host: 91.200.14.153
Date added:2025-05-03 11:49:09 UTC
Last online:2025-05-19 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-05-03 11:50:09 UTC to abuse{at}h2[dot]nexus)
Takedown time:16 days, 1 hours, 20 minutes Bad (down since 2025-05-19 13:11:02 UTC)
Tags:AsyncRAT link xml-opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-10window.exeexe 73fdfd680339611d92c6327e9aaefa395d2dc11bca2493d9f4fb9c1b4bdcd9efVirustotal results 7.04% AurotunStealer
2025-05-05window.exeexe dd8db8db97b2347fb5d250abec7ef56b87ac635f2e93546c2b6fabc2e4203e7en/aAsyncRAT
2025-05-03window.exeexe 1a4a1fc4c3ddccb8efcaaab7fa0ba3965e2244fa0733100e56122354e7bb721aVirustotal results 16.90% AsyncRAT