URLhaus Database

You are currently viewing the URLhaus database entry for http://167.160.161.248/v9d9d.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3599470
URL: http://167.160.161.248/v9d9d.exe
URL Status:Offline
Host: 167.160.161.248
Date added:2025-08-09 06:08:34 UTC
Last online:2025-08-15 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-08-09 12:13:12 UTC to abuse{at}virtualine[dot]org)
Takedown time:6 days, 4 hours, 50 minutes Bad (down since 2025-08-15 17:03:44 UTC)
Tags:exe Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-14v9d9d.exeexe 989e84e3c0e940df3edd50cfdc5173bfbbacca2aebe5f0ef21e28abdeefb7338Virustotal results 33.33%Vidar
2025-08-14v9d9d.exeexe 95a86f8b4ac54d0bd92bd8e16960df8291b50cbeef9d0a2986c150e2398c4ad5n/aVidar
2025-08-09v9d9d.exeexe aa49684e48cdc3a3b706973c0c55fd1a2be03aa0337e15810db20f6a08c127a9Virustotal results 60.00%Vidar