URLhaus Database

You are currently viewing the URLhaus database entry for http://91.92.240.104/JAMMX4im1BtsCSq.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3626883
URL: http://91.92.240.104/JAMMX4im1BtsCSq.exe
URL Status:flame Online (spreading malware for 2 months, 2 days, 14 hours, 39 minutes)
Host: 91.92.240.104
Date added:2025-09-19 08:18:05 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-09-19 08:19:10 UTC to abuse{at}metaspinner[dot]net)
Tags:exe MassLogger link VIPKeylogger

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-23JAMMX4im1BtsCSq.exeexe e24ecde3ff566263efe49ba6614108d122e1bd90b5857d372398c3b852a93167Virustotal results 38.89% MassLogger
2025-09-23JAMMX4im1BtsCSq.exeexe 7fb19749386184cbfb206eb2b5607b747925df90586062f2f74a9fd575030f9eVirustotal results 30.56% MassLogger
2025-09-19JAMMX4im1BtsCSq.exeexe dfff02076554af2576fd4b55b593d4923e19d7a5b0596ca4162c9101bed25691Virustotal results 39.13%VIPKeylogger