URLhaus Database

You are currently viewing the URLhaus database entry for http://185.156.72.2/files/5561582465/oSOnryg.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3569164
URL: http://185.156.72.2/files/5561582465/oSOnryg.exe
URL Status:Offline
Host: 185.156.72.2
Date added:2025-06-22 13:26:12 UTC
Last online:2025-06-28 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-06-22 13:27:11 UTC to erishennya[dot]res{at}gmail[dot]com)
Takedown time:6 days, 3 hours, 29 minutes Bad (down since 2025-06-28 16:56:54 UTC)
Tags:c2-monitor-auto dropped-by-amadey

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-28oSOnryg.exeexe d78523952a9763a152b876dd267e37536ff7e021f04091ec5e0cb0b6ec3e4a37n/a
2025-06-27oSOnryg.exeexe fa5d338ee8483ad12b2e852abc5dc7fe811fcb76456a1afb646722cde0e3deafVirustotal results 27.69%
2025-06-27oSOnryg.exeexe c717e683654e28a1a430c5d81a8cc9c3f7b9363edc66f54f4fe0b80a666745den/a 
2025-06-26oSOnryg.exeexe 5d7cb19429bea7810fd4dcfa3bca524e2414a4173116244f56f52f56e047bde0n/a 
2025-06-26oSOnryg.exeexe 9c05fb7edf15fd71f18bd64c620a35aa8a3298fa79920b938e31c531484b8c3aVirustotal results 18.31% 
2025-06-25oSOnryg.exeexe 04994178a60db8035bfd908499d75b3e5d9c37d8ee6b840b3a1ba311ccefc459Virustotal results 22.22% 
2025-06-25oSOnryg.exeexe 782969341bc7eb5a0c4659566761bb41307b7827e56546dc942de82b599dcbd9Virustotal results 23.61%
2025-06-24oSOnryg.exeexe dfcf1470307ddc76e6e43de3f49a86c8065f3cd1c3e1613cf92ab15858bb0b74Virustotal results 26.39%
2025-06-24oSOnryg.exeexe dbecad520b014caae6ffc29e5c6235051d0c00147407afb5427fd4731faf9389Virustotal results 22.22%
2025-06-23oSOnryg.exeexe a2a5a1cb1adeb94afc8ad2f685927a25e64c28a870c948014cbb864c18241fd0Virustotal results 26.47% 
2025-06-23oSOnryg.exeexe e5341a517390646a0b6781c24ca0b5b85a266dcbf8546d95f15bcd9cd6db830fVirustotal results 23.61% 
2025-06-22oSOnryg.exeexe 99b3e6c422b79b6380e218c32b400485c202c2fb89444a1c047a92e17049fce1Virustotal results 22.54%