URLhaus Database

You are currently viewing the URLhaus database entry for http://80.64.18.161/test/exe/random.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3538339
URL: http://80.64.18.161/test/exe/random.exe
URL Status:Offline
Host: 80.64.18.161
Date added:2025-05-08 05:10:11 UTC
Last online:2025-05-13 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-05-08 05:11:07 UTC to abuse{at}stimllc[dot]ru)
Takedown time:5 days, 7 hours, 1 minutes Bad (down since 2025-05-13 12:12:47 UTC)
Tags:Amadey

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-10random.exeexe c3d9be0793c045f428f174a4d4f9f314d449a75bbb15dccd5756c84c137bac4bVirustotal results 57.38% 
2025-05-09random.exeexe 52c72951c10260de19b06711ae501040976b293a4d19723b978198838cf9de65Virustotal results 46.48% CredentialFlusher
2025-05-09random.exeexe 5fc95a116299507a7153bd8a1a58454f3ba6876185af3b7f4a95f939385111ebn/a Amadey
2025-05-09random.exeexe 75ac9ae7e1586463fb664aa02d1bb631f045e168203df1daae684560b7bb0b45n/a CredentialFlusher
2025-05-08random.exeexe 5f199638dcaa09b346b92146c4984fda000d5728ee53d8ece558b87a8e1544fcn/a CredentialFlusher
2025-05-08random.exeexe 98f683cb9070b1fe1c8956de214cfe1957f6f3a4ccfc0d2c30ea0168490461c8n/a Amadey
2025-05-08random.exeexe 9221b2af0730a16a53affaa4c7fb22c4e291773f3a426f8fe4fcb4ece0d90172Virustotal results 47.22% Amadey
2025-05-08random.exeexe fdca77b6436464c9c8a1996214f7c1703964474bc997a1ccb85760ecb91b69fbn/a CredentialFlusher
2025-05-08random.exeexe 5d1832bff714c3c6c0f5282ed888e7bdd5088957e961627f2ef5c382525eb8e6n/a Amadey
2025-05-08random.exeexe c28bdc6a23e081607d4e41ce926b652cbad558e6a2d5161dd75fd071cb205faen/a Amadey
2025-05-08random.exeexe 4a0079f58be04e4f3bbf5ba271cde8e6629d2d8c0a99760bf2d6e06fc94fe146Virustotal results 45.83% CredentialFlusher
2025-05-08random.exeexe 48d2a3bfbe07c2346476f347d88bc3c205c2f552967c1a798515fa39836c4425n/a Amadey