URLhaus Database

You are currently viewing the URLhaus database entry for http://213.209.150.18/U74238PyCPCGN9I.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3611744
URL: http://213.209.150.18/U74238PyCPCGN9I.exe
URL Status:Offline
Host: 213.209.150.18
Date added:2025-08-26 07:16:06 UTC
Last online:2025-09-15 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-08-26 07:17:11 UTC to abuse{at}virtualine[dot]org)
Takedown time:20 days, 8 hours, 11 minutes Bad (down since 2025-09-15 15:28:45 UTC)
Tags:exe MassLogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-29U74238PyCPCGN9I.exeexe 8664e2d8740f46f1cc7caf3c7f0cec7248953eef593508ab9a960b332c2e2129n/a MassLogger
2025-08-28U74238PyCPCGN9I.exeexe 9204f13869b4651d60a200236c8d4dd48a6f0dc3734ab6dc6a90d9dfbb239139Virustotal results 36.11% 
2025-08-28U74238PyCPCGN9I.exeexe e807c3281a807e5051c4f0e14aa7e1fb3403d58470aa0f4ebfb61ffbc849b91bn/a MassLogger
2025-08-27U74238PyCPCGN9I.exeexe 2b349e5afa8fc892adee56dcf24e4898f9ee827ae9e797dd3811a6de279c3becn/a MassLogger
2025-08-27U74238PyCPCGN9I.exeexe 92e7e61849bf174d73eeee670f0b7886f67e3acca0f660654d19f226e8e2802cn/a 
2025-08-26U74238PyCPCGN9I.exeexe ebf097ae191b7bef64fd815f7aaa3a7202a9914cf227dcb5fdc0affbdb6bc0f9n/a MassLogger
2025-08-26U74238PyCPCGN9I.exeexe 44f1a67e4a326b1f751b8e0671a46ff65acd9c8e9c515c764c41c87c3bf9cca8Virustotal results 36.11%MassLogger