URLhaus Database

You are currently viewing the URLhaus database entry for http://91.92.240.104/XPQeEQubuBaya8g.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3631855
URL: http://91.92.240.104/XPQeEQubuBaya8g.exe
URL Status:flame Online (spreading malware for 1 month, 26 days, 8 hours, 1 minutes)
Host: 91.92.240.104
Date added:2025-09-25 14:53:08 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-09-25 14:54:11 UTC to abuse{at}metaspinner[dot]net)
Tags:exe MassLogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-01XPQeEQubuBaya8g.exeexe cbbec8fcc0e23e23bcdce82ab97533c7b49f0bcac924cf254a2a8d02b9594ac5n/a MassLogger
2025-09-30XPQeEQubuBaya8g.exeexe 6c83a9184b6211c78f327049671f8e577019c1a8c4302877c9f7cbf526f19847Virustotal results 52.11% MassLogger
2025-09-29XPQeEQubuBaya8g.exeexe cf38cbbec69960f5e13dea99b14f887f427737cf32f5ab2259a9c5ff20680614Virustotal results 51.39% MassLogger
2025-09-29XPQeEQubuBaya8g.exeexe 818e87f260550fb8333e48a70d5ffdbf0a22b766d4eeac974f30db64aa617584n/a MassLogger
2025-09-25XPQeEQubuBaya8g.exeexe 8a7744ef7ff9df61995edc1cd227d72c4ccbe86764e99f22d38ad9e6d94e9b0eVirustotal results 54.17%MassLogger