URLhaus Database

You are currently viewing the URLhaus database entry for http://213.209.150.18/uCoAIgy7ON5dnXN.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3612435
URL: http://213.209.150.18/uCoAIgy7ON5dnXN.exe
URL Status:Offline
Host: 213.209.150.18
Date added:2025-08-27 09:10:07 UTC
Last online:2025-09-15 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-08-27 09:11:10 UTC to abuse{at}virtualine[dot]org)
Takedown time:19 days, 6 hours, 57 minutes Bad (down since 2025-09-15 16:08:41 UTC)
Tags:exe MassLogger link VIPKeylogger

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-28uCoAIgy7ON5dnXN.exeexe cb823f677730c087847c75a7da3c0d5dbfedfbf31f757e37a7ca566fb5c7074cVirustotal results 36.11% MassLogger
2025-08-28uCoAIgy7ON5dnXN.exeexe 6b5d00db3ce229393f7dcfe8b8c4bec3cebbdd7bfe293475a4856cfdf0660cd0n/a 
2025-08-27uCoAIgy7ON5dnXN.exeexe 259ad0de4cc1f77279c2efb6c3d3f5fcf7655013c8f116d25a18c697faab5f45Virustotal results 55.56%VIPKeylogger
2025-08-27uCoAIgy7ON5dnXN.exeexe d674ac095490af3430ec4ec50b1be905b1e7f690117da522c447332d78d25bb9Virustotal results 34.72%MassLogger