URLhaus Database

You are currently viewing the URLhaus database entry for http://176.46.157.32/files/8111443583/YT1For2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3583516
URL: http://176.46.157.32/files/8111443583/YT1For2.exe
URL Status:Offline
Host: 176.46.157.32
Date added:2025-07-15 05:53:07 UTC
Last online:2025-07-23 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-07-15 05:54:13 UTC to luke[dot]ross{at}mnttr[dot]com)
Takedown time:8 days, 4 hours, 43 minutes Bad (down since 2025-07-23 10:37:48 UTC)
Tags:AsyncRAT link c2-monitor-auto dropped-by-amadey QuasarRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-07-17YT1For2.exeexe 01cb5a170ccb486184841f7adf57026bf18fdd25d71824ebe40161256a3f1f9bVirustotal results 50.00% QuasarRAT
2025-07-16YT1For2.exeexe c85f8d6b170cb82a16394039a902ff3e382ccf1fc9bf35960116fdad27846ff6Virustotal results 56.94% AsyncRAT
2025-07-16YT1For2.exeexe 11da28df3b916bde4ab4beb581416169b51b1d1f8aa30f1ed4398323f837bf0bVirustotal results 56.94% AsyncRAT
2025-07-15YT1For2.exeexe e56d433df3b26e1279ba129075c01b7411669188b1553ec7a6b6a6c64f87e887Virustotal results 8.33%