URLhaus Database

You are currently viewing the URLhaus database entry for http://91.92.240.104/vq7qNSPpTLL2NJm.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3626039
URL: http://91.92.240.104/vq7qNSPpTLL2NJm.exe
URL Status:flame Online (spreading malware for 2 months, 3 days, 5 hours, 23 minutes)
Host: 91.92.240.104
Date added:2025-09-18 07:23:06 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-09-18 07:24:10 UTC to abuse{at}metaspinner[dot]net)
Tags:exe MassLogger link VIPKeylogger

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-23vq7qNSPpTLL2NJm.exeexe e24ecde3ff566263efe49ba6614108d122e1bd90b5857d372398c3b852a93167Virustotal results 38.89% MassLogger
2025-09-23vq7qNSPpTLL2NJm.exeexe 7fb19749386184cbfb206eb2b5607b747925df90586062f2f74a9fd575030f9eVirustotal results 30.56% MassLogger
2025-09-19vq7qNSPpTLL2NJm.exeexe dfff02076554af2576fd4b55b593d4923e19d7a5b0596ca4162c9101bed25691Virustotal results 29.17%VIPKeylogger
2025-09-18vq7qNSPpTLL2NJm.exeexe a2baea783b7929235c15f8b354fdb7a4dc5a251c97a0c3973cedd4eaa6dccf2aVirustotal results 29.58%MassLogger
2025-09-18vq7qNSPpTLL2NJm.exeexe 0d41bec1e1df871d2a73908ea7f03498e78f8f75a65e87a7d863e333e1d4e65fVirustotal results 37.50%VIPKeylogger