URLhaus Database

You are currently viewing the URLhaus database entry for http://91.92.240.104/gbIM8JUazFGEAPH.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3624994
URL: http://91.92.240.104/gbIM8JUazFGEAPH.exe
URL Status:flame Online (spreading malware for 2 months, 5 days, 4 hours, 16 minutes)
Host: 91.92.240.104
Date added:2025-09-16 08:29:10 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-09-16 08:30:13 UTC to abuse{at}metaspinner[dot]net)
Tags:exe MassLogger link VIPKeylogger

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-19gbIM8JUazFGEAPH.exeexe dfff02076554af2576fd4b55b593d4923e19d7a5b0596ca4162c9101bed25691Virustotal results 39.13%VIPKeylogger
2025-09-18gbIM8JUazFGEAPH.exeexe a2baea783b7929235c15f8b354fdb7a4dc5a251c97a0c3973cedd4eaa6dccf2aVirustotal results 29.58%MassLogger
2025-09-17gbIM8JUazFGEAPH.exeexe 0d41bec1e1df871d2a73908ea7f03498e78f8f75a65e87a7d863e333e1d4e65fVirustotal results 37.50%VIPKeylogger
2025-09-17gbIM8JUazFGEAPH.exeexe a23d8b5d3f4d555dd5038bbc14061f968f087a8fbd3ab869ba7e551022db80f8Virustotal results 41.67% MassLogger
2025-09-16gbIM8JUazFGEAPH.exeexe bb7ccc846a2a8b6352e336a048afc0cbb76c6fb2d2c523bacc09c5f2a443e964Virustotal results 50.00% MassLogger
2025-09-16gbIM8JUazFGEAPH.exeexe 43ed1aebae3195013c937d690ccae41ba4453cd6b21567f2e9504e45c33650a9n/a MassLogger