URLhaus Database

You are currently viewing the URLhaus database entry for http://196.251.87.163/download which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3611622
URL: http://196.251.87.163/download
URL Status:Offline
Host: 196.251.87.163
Date added:2025-08-26 05:24:29 UTC
Last online:2025-09-05 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: burger
Abuse complaint sent (?): Yes (2025-08-26 05:25:45 UTC to abuse{at}cheapy[dot]host)
Takedown time:9 days, 20 hours, 53 minutes Bad (down since 2025-09-05 02:19:00 UTC)
Tags:exe GenesisStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-03panel.exeexe c6f837510557f1630ad2c415ba0670e73dfd50daa65379a2d941dbfd248f2738Virustotal results 4.23% 
2025-09-01panel.exeexe 723e1087a0091ef040dd5b74fb59362dd78895a32451e0e0e1d9d1081060bb04Virustotal results 5.63% 
2025-08-28panel.exeexe 7d376db594d7e8a305209dc7ff75a0cfa368d4991a6e8c1da639e10426797362n/a 
2025-08-26panel.exeexe 6812094fa5eb02d7835e91b8f056dcb73a018ff4182637ff6f957ea6f06209ddn/a 
2025-08-26panel.exeexe 50a362c59eac4bd2d6c3e211f3cdd661653f49d5050806f698949c7211ac6a7bVirustotal results 5.71%GenesisStealer