URLhaus Database

You are currently viewing the URLhaus database entry for http://45.141.233.196/download.php which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3605707
URL: http://45.141.233.196/download.php
URL Status:Offline
Host: 45.141.233.196
Date added:2025-08-18 09:15:09 UTC
Last online:2025-08-19 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-08-18 09:16:13 UTC to abuse{at}virtualine[dot]org)
Takedown time:1 day, 10 hours, 48 minutes Poor (down since 2025-08-19 20:05:08 UTC)
Tags:Amadey ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-19random.exeexe dff3e8374235355d6590e3eac942db3f4093846fa0fc7d321193948d9b9074f1n/a Amadey
2025-08-19random.exeexe b2ed1a03c6c83f4abc16d5519df3d75f383c370ce2a7981623469a9263f94b7en/a Amadey
2025-08-19random.exeexe 9898bd4e11a25ab7fb1dbecb04410a3da78b8f136cc010361ebc65a026d739ban/a Amadey
2025-08-19random.exeexe 634f38130e9aa2df80bdedc32e91c68fca95f476a7e35b4023ee1c096474721bn/a Amadey
2025-08-18random.exeexe deda382a146c77c559b57a02195499280d1b2544d94315b635c09cc0fac09364n/a Amadey
2025-08-18random.exeexe b3bfa1c76a8ce451b6e0464b8dfe458ecc40dd330421eff29d78f0defc3df6ddn/a Amadey
2025-08-18random.exeexe f499d9aae6dda3812ad602add897087f7b78d4f890d4b86d18ab34ae86aebbb6n/a Amadey