URLhaus Database

You are currently viewing the URLhaus database entry for http://193.32.176.219/UPZDKGAF.bin which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3581742
URL: http://193.32.176.219/UPZDKGAF.bin
URL Status:Offline
Host: 193.32.176.219
Date added:2025-07-12 05:48:11 UTC
Last online:2025-07-22 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: aachum
Abuse complaint sent (?): Yes (2025-07-12 05:49:20 UTC to abuse{at}globconnex[dot]com)
Takedown time:10 days, 17 hours, 6 minutes Bad (down since 2025-07-22 22:55:29 UTC)
Tags:dropped-by-ACRStealer Gh0stRAT HijackLoader IDATLoader

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-07-19UPZDKGAF.binexe e248994d1e415aeb2ec170f513316130788bbb05545e5fb9f662d64f3103195bVirustotal results 11.11%
2025-07-17UPZDKGAF.binexe e9c01cbcefd682be349b6ff9f91e3685a9c5a379e8417b00753d5021223603c4n/a Gh0stRAT
2025-07-16UPZDKGAF.binexe dc2f86c451c9939d338b199a7119464ef5f08e2a8d54b7baf0b7ecf15905b652n/a Gh0stRAT
2025-07-15UPZDKGAF.binexe eed5f9d02a1ac26d2b52bc1e4bafa73073faed0bb665687ddcf90dcecb41b878n/a
2025-07-12UPZDKGAF.binexe 4a2c9d7bede240c16a028a9ce884af292ef1f0dbdb76d5c2ea04db2d9f36c1f4Virustotal results 36.11%HijackLoader