URLhaus Database

You are currently viewing the URLhaus database entry for http://94.154.35.115/user_profiles_photo/update.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3550926
URL: http://94.154.35.115/user_profiles_photo/update.exe
URL Status:Offline
Host: 94.154.35.115
Date added:2025-05-23 15:41:10 UTC
Last online:2025-11-11 01:XX:XX UTC
Threat:Malware download Malware download
Reporter: skocherhan
Abuse complaint sent (?): Yes (2025-05-23 15:42:18 UTC to abuse{at}pitline[dot]net,abusep{at}kharkiv[dot]com)
Takedown time:5 months, 21 days, 9 hours, 22 minutes Bad (down since 2025-11-11 01:05:10 UTC)
Tags:PureLogStealer Rhadamanthys

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-28update.exeexe 030eac7d568cdbcf9ab1015ca14a0e392c54eaa4e0b15c77ee659ff1d4432d29Virustotal results 66.67% 
2025-05-26update.exeexe b2b81e7c844bd14b20faea55ff857d2e6208f879480b05e0c0ca698c911b9bbcn/aPureLogStealer
2025-05-25update.exeexe 90fd739417949041659758462e21f32f877a8338aa9300835e25ec3370cf2d4en/a Rhadamanthys
2025-05-23update.exeexe ee3a4a2e8055495e761c88db214b85a6a27852678fd6f07efc9a9328a3fb7d03n/aPureLogStealer
2025-05-23update.exeexe 59ab63c99285e35679153e299e411aa32a94d25482566428a6fd7d908f04d4adVirustotal results 81.94%PureLogStealer