URLhaus Database

You are currently viewing the URLhaus database entry for http://195.201.227.130/xex/ch0m.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3610821
URL: http://195.201.227.130/xex/ch0m.exe
URL Status:Offline
Host: 195.201.227.130
Date added:2025-08-24 14:17:36 UTC
Last online:2025-08-27 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: aachum
Abuse complaint sent (?): Yes (2025-08-24 14:18:14 UTC to abuse{at}hetzner[dot]com)
Takedown time:2 days, 12 hours, 3 minutes Poor (down since 2025-08-27 02:21:48 UTC)
Tags:ClickFix FakeCaptcha Rhadamanthys

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-25ch0m.exeexe 516d9daee48799c22090e64835e99df3d6a6384e9305bfa90287486c4e9881beVirustotal results 20.83%Rhadamanthys
2025-08-24ch0m.exeexe 5840ea1c615a9daee7648736117ddce1c7c6e2143bf3b971e6828989e094edc4Virustotal results 25.71%Rhadamanthys
2025-08-24ch0m.exeexe 03fe53eff294a718d3a887e23e2e83c98c55e8b6b5654bbc6650400f011604adVirustotal results 47.22%Rhadamanthys